SYMBOLCOMMON_NAMEaka. SYNONYMS
win.dusttrap (Back to overview)

DUSTTRAP

aka: CurveLoad, DodgeBox, StealthReacher

Actor(s): APT41

VTCollection    

There is no description at this point.

References
2024-07-18 ⋅ Mandiant ⋅ Mike Stokkel
APT41 Has Arisen From the DUST
DUSTTRAP PINEGROVE
2024-07-10 ⋅ Zscaler ⋅ Sudeep Singh, Yin Hong Chang
DodgeBox: A deep dive into the updated arsenal of APT41 | Part 1
Cobalt Strike DUSTPAN DUSTTRAP
Yara Rules
[TLP:WHITE] win_dusttrap_auto (20260917 | Detects win.dusttrap.)
rule win_dusttrap_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.dusttrap."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dusttrap"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 7219 8b4f38 418b10 ffca 03d1 f7d9 23d1 }
            // n = 7, score = 100
            //   7219                 | xor                 esi, eax
            //   8b4f38               | xor                 esi, ebp
            //   418b10               | mov                 edi, esi
            //   ffca                 | shl                 esi, 8
            //   03d1                 | inc                 edx
            //   f7d9                 | movzx               eax, byte ptr [ecx + esi]
            //   23d1                 | xor                 esi, eax

        $sequence_1 = { 0fb6423a 0fb65a3b 0fb6723f 418d8c2478a46ad7 }
            // n = 4, score = 100
            //   0fb6423a             | inc                 esp
            //   0fb65a3b             | mov                 esi, ebx
            //   0fb6723f             | dec                 ecx
            //   418d8c2478a46ad7     | mov                 eax, esp

        $sequence_2 = { 03c2 8b9424f0000000 81c2051d8804 03d0 c1ca09 4103d0 8bc2 }
            // n = 7, score = 100
            //   03c2                 | movzx               eax, byte ptr [edi + edi]
            //   8b9424f0000000       | xor                 al, byte ptr [ebx + ebp]
            //   81c2051d8804         | mov                 byte ptr [edi], al
            //   03d0                 | inc                 esp
            //   c1ca09               | mov                 esi, eax
            //   4103d0               | test                eax, eax
            //   8bc2                 | jne                 0x1de9

        $sequence_3 = { 448b457f 41ffc4 418bc4 4883c30c 483bc1 0f8272feffff 4881c4c8000000 }
            // n = 7, score = 100
            //   448b457f             | dec                 eax
            //   41ffc4               | add                 esp, 0x110
            //   418bc4               | pop                 ebp
            //   4883c30c             | ret                 
            //   483bc1               | dec                 eax
            //   0f8272feffff         | mov                 ebx, dword ptr [esp + 0x410]
            //   4881c4c8000000       | inc                 esp

        $sequence_4 = { 4983ceff 4d8be1 498be8 4c8bea 498b84ffc8bf0200 90 }
            // n = 6, score = 100
            //   4983ceff             | inc                 ebp
            //   4d8be1               | mov                 edx, dword ptr [edi]
            //   498be8               | je                  0xc1a
            //   4c8bea               | dec                 ecx
            //   498b84ffc8bf0200     | mov                 ecx, edi
            //   90                   | test                eax, eax

        $sequence_5 = { 448d4203 488b4920 e8???????? 4c8bf8 488bd3 0f1f840000000000 48ffc2 }
            // n = 7, score = 100
            //   448d4203             | mov                 ecx, esi
            //   488b4920             | inc                 esp
            //   e8????????           |                     
            //   4c8bf8               | mov                 ecx, dword ptr [eax + esi + 0x28]
            //   488bd3               | dec                 esp
            //   0f1f840000000000     | add                 ecx, esi
            //   48ffc2               | inc                 ecx

        $sequence_6 = { 0f1005???????? 418bc2 4c8d4df0 0f100d???????? 41b820000000 488d55d0 0f1145d0 }
            // n = 7, score = 100
            //   0f1005????????       |                     
            //   418bc2               | pop                 edi
            //   4c8d4df0             | inc                 ecx
            //   0f100d????????       |                     
            //   41b820000000         | pop                 ebp
            //   488d55d0             | inc                 esp
            //   0f1145d0             | lea                 eax, [edx + 3]

        $sequence_7 = { 448bf6 4903df 4981c600ffffff 33d2 41b820030000 4c03f3 e8???????? }
            // n = 7, score = 100
            //   448bf6               | dec                 eax
            //   4903df               | mov                 eax, edi
            //   4981c600ffffff       | inc                 eax
            //   33d2                 | cmp                 byte ptr [eax], ch
            //   41b820030000         | jne                 0x1d67
            //   4c03f3               | inc                 ecx
            //   e8????????           |                     

        $sequence_8 = { bab0070bfe 41b847548cfd 48894128 488d0dc8010200 e8???????? 488b0d???????? bab0070bfe }
            // n = 7, score = 100
            //   bab0070bfe           | dec                 esp
            //   41b847548cfd         | mov                 dword ptr [esp + 0xd8], edi
            //   48894128             | dec                 eax
            //   488d0dc8010200       | mov                 dword ptr [esp + 0x30], ecx
            //   e8????????           |                     
            //   488b0d????????       |                     
            //   bab0070bfe           | dec                 eax

        $sequence_9 = { 4889442428 488d442450 48895c2458 488b4940 4c8d4aff 4c897c2450 448d4204 }
            // n = 7, score = 100
            //   4889442428           | dec                 eax
            //   488d442450           | mov                 dword ptr [esp + 0x30], ebp
            //   48895c2458           | xor                 edx, edx
            //   488b4940             | dec                 eax
            //   4c8d4aff             | mov                 dword ptr [esp + 0x28], ebp
            //   4c897c2450           | dec                 eax
            //   448d4204             | lea                 eax, [esp + 0xa8]

    condition:
        7 of them and filesize < 421888
}
Download all Yara Rules