SYMBOLCOMMON_NAMEaka. SYNONYMS
win.donot (Back to overview)

DONOT

Actor(s): VICEROY TIGER

VTCollection    

Donot malware is a sophisticated, high-level malware toolkit designed to collect and exfiltrate information from vulnerable systems. It has been used in targeted attacks against government and military organizations in Asia. Donot malware is highly complex and well-crafted, and it poses a serious threat to information security.

References
2024-05-14 ⋅ Check Point Research ⋅ Antonis Terefos, Tera0017
Foxit PDF “Flawed Design” Exploitation
Rafel RAT Agent Tesla AsyncRAT DCRat DONOT Nanocore RAT NjRAT Pony Remcos Venom RAT XWorm
2023-02-23 ⋅ K7 Security ⋅ Vigneshwaran P
The DoNot APT
DONOT
2022-08-11 ⋅ Morphisec ⋅ Arnold Osipov, Hido Cohen
APT-C-35 GETS A NEW UPGRADE
DONOT
Yara Rules
[TLP:WHITE] win_donot_auto (20260917 | Detects win.donot.)
rule win_donot_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.donot."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.donot"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 0f8416010000 8bc2 83f910 7202 8b02 8a1c18 0fb6c3 }
            // n = 7, score = 100
            //   0f8416010000         | je                  0x11c
            //   8bc2                 | mov                 eax, edx
            //   83f910               | cmp                 ecx, 0x10
            //   7202                 | jb                  4
            //   8b02                 | mov                 eax, dword ptr [edx]
            //   8a1c18               | mov                 bl, byte ptr [eax + ebx]
            //   0fb6c3               | movzx               eax, bl

        $sequence_1 = { 8945fc e8???????? 8b4dfc 83c40c 8b55f4 03cb 2bd1 }
            // n = 7, score = 100
            //   8945fc               | mov                 dword ptr [ebp - 4], eax
            //   e8????????           |                     
            //   8b4dfc               | mov                 ecx, dword ptr [ebp - 4]
            //   83c40c               | add                 esp, 0xc
            //   8b55f4               | mov                 edx, dword ptr [ebp - 0xc]
            //   03cb                 | add                 ecx, ebx
            //   2bd1                 | sub                 edx, ecx

        $sequence_2 = { 64a300000000 8bf9 897dec 8b07 8b4004 c70407???????? }
            // n = 6, score = 100
            //   64a300000000         | mov                 dword ptr fs:[0], eax
            //   8bf9                 | mov                 edi, ecx
            //   897dec               | mov                 dword ptr [ebp - 0x14], edi
            //   8b07                 | mov                 eax, dword ptr [edi]
            //   8b4004               | mov                 eax, dword ptr [eax + 4]
            //   c70407????????       |                     

        $sequence_3 = { e8???????? 51 68???????? 8d8590fdffff 50 }
            // n = 5, score = 100
            //   e8????????           |                     
            //   51                   | push                ecx
            //   68????????           |                     
            //   8d8590fdffff         | lea                 eax, [ebp - 0x270]
            //   50                   | push                eax

        $sequence_4 = { 6a01 ff12 837f3800 8a450b 884740 7510 8b470c }
            // n = 7, score = 100
            //   6a01                 | push                1
            //   ff12                 | call                dword ptr [edx]
            //   837f3800             | cmp                 dword ptr [edi + 0x38], 0
            //   8a450b               | mov                 al, byte ptr [ebp + 0xb]
            //   884740               | mov                 byte ptr [edi + 0x40], al
            //   7510                 | jne                 0x12
            //   8b470c               | mov                 eax, dword ptr [edi + 0xc]

        $sequence_5 = { 898538ffffff 8d8528ffffff 0f438528ffffff 03f0 56 e8???????? }
            // n = 6, score = 100
            //   898538ffffff         | mov                 dword ptr [ebp - 0xc8], eax
            //   8d8528ffffff         | lea                 eax, [ebp - 0xd8]
            //   0f438528ffffff       | cmovae              eax, dword ptr [ebp - 0xd8]
            //   03f0                 | add                 esi, eax
            //   56                   | push                esi
            //   e8????????           |                     

        $sequence_6 = { 0f829cf8ffff 8b8df4ecffff 42 8bc1 81fa00100000 0f827df8ffff 8b49fc }
            // n = 7, score = 100
            //   0f829cf8ffff         | jb                  0xfffff8a2
            //   8b8df4ecffff         | mov                 ecx, dword ptr [ebp - 0x130c]
            //   42                   | inc                 edx
            //   8bc1                 | mov                 eax, ecx
            //   81fa00100000         | cmp                 edx, 0x1000
            //   0f827df8ffff         | jb                  0xfffff883
            //   8b49fc               | mov                 ecx, dword ptr [ecx - 4]

        $sequence_7 = { c705????????0f000000 c705????????00000000 c705????????00000000 c705????????0f000000 6a08 68???????? b9???????? }
            // n = 7, score = 100
            //   c705????????0f000000     |     
            //   c705????????00000000     |     
            //   c705????????00000000     |     
            //   c705????????0f000000     |     
            //   6a08                 | push                8
            //   68????????           |                     
            //   b9????????           |                     

        $sequence_8 = { ff24859cb70110 b801000000 5d c3 b802000000 5d c3 }
            // n = 7, score = 100
            //   ff24859cb70110       | jmp                 dword ptr [eax*4 + 0x1001b79c]
            //   b801000000           | mov                 eax, 1
            //   5d                   | pop                 ebp
            //   c3                   | ret                 
            //   b802000000           | mov                 eax, 2
            //   5d                   | pop                 ebp
            //   c3                   | ret                 

        $sequence_9 = { 0f43c7 0fbe0c10 85c9 7e13 }
            // n = 4, score = 100
            //   0f43c7               | cmovae              eax, edi
            //   0fbe0c10             | movsx               ecx, byte ptr [eax + edx]
            //   85c9                 | test                ecx, ecx
            //   7e13                 | jle                 0x15

    condition:
        7 of them and filesize < 626688
}
Download all Yara Rules