Actor(s): APT41
There is no description at this point.
rule win_dusttrap_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.dusttrap." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dusttrap" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 7219 8b4f38 418b10 ffca 03d1 f7d9 23d1 } // n = 7, score = 100 // 7219 | xor esi, eax // 8b4f38 | xor esi, ebp // 418b10 | mov edi, esi // ffca | shl esi, 8 // 03d1 | inc edx // f7d9 | movzx eax, byte ptr [ecx + esi] // 23d1 | xor esi, eax $sequence_1 = { 0fb6423a 0fb65a3b 0fb6723f 418d8c2478a46ad7 } // n = 4, score = 100 // 0fb6423a | inc esp // 0fb65a3b | mov esi, ebx // 0fb6723f | dec ecx // 418d8c2478a46ad7 | mov eax, esp $sequence_2 = { 03c2 8b9424f0000000 81c2051d8804 03d0 c1ca09 4103d0 8bc2 } // n = 7, score = 100 // 03c2 | movzx eax, byte ptr [edi + edi] // 8b9424f0000000 | xor al, byte ptr [ebx + ebp] // 81c2051d8804 | mov byte ptr [edi], al // 03d0 | inc esp // c1ca09 | mov esi, eax // 4103d0 | test eax, eax // 8bc2 | jne 0x1de9 $sequence_3 = { 448b457f 41ffc4 418bc4 4883c30c 483bc1 0f8272feffff 4881c4c8000000 } // n = 7, score = 100 // 448b457f | dec eax // 41ffc4 | add esp, 0x110 // 418bc4 | pop ebp // 4883c30c | ret // 483bc1 | dec eax // 0f8272feffff | mov ebx, dword ptr [esp + 0x410] // 4881c4c8000000 | inc esp $sequence_4 = { 4983ceff 4d8be1 498be8 4c8bea 498b84ffc8bf0200 90 } // n = 6, score = 100 // 4983ceff | inc ebp // 4d8be1 | mov edx, dword ptr [edi] // 498be8 | je 0xc1a // 4c8bea | dec ecx // 498b84ffc8bf0200 | mov ecx, edi // 90 | test eax, eax $sequence_5 = { 448d4203 488b4920 e8???????? 4c8bf8 488bd3 0f1f840000000000 48ffc2 } // n = 7, score = 100 // 448d4203 | mov ecx, esi // 488b4920 | inc esp // e8???????? | // 4c8bf8 | mov ecx, dword ptr [eax + esi + 0x28] // 488bd3 | dec esp // 0f1f840000000000 | add ecx, esi // 48ffc2 | inc ecx $sequence_6 = { 0f1005???????? 418bc2 4c8d4df0 0f100d???????? 41b820000000 488d55d0 0f1145d0 } // n = 7, score = 100 // 0f1005???????? | // 418bc2 | pop edi // 4c8d4df0 | inc ecx // 0f100d???????? | // 41b820000000 | pop ebp // 488d55d0 | inc esp // 0f1145d0 | lea eax, [edx + 3] $sequence_7 = { 448bf6 4903df 4981c600ffffff 33d2 41b820030000 4c03f3 e8???????? } // n = 7, score = 100 // 448bf6 | dec eax // 4903df | mov eax, edi // 4981c600ffffff | inc eax // 33d2 | cmp byte ptr [eax], ch // 41b820030000 | jne 0x1d67 // 4c03f3 | inc ecx // e8???????? | $sequence_8 = { bab0070bfe 41b847548cfd 48894128 488d0dc8010200 e8???????? 488b0d???????? bab0070bfe } // n = 7, score = 100 // bab0070bfe | dec esp // 41b847548cfd | mov dword ptr [esp + 0xd8], edi // 48894128 | dec eax // 488d0dc8010200 | mov dword ptr [esp + 0x30], ecx // e8???????? | // 488b0d???????? | // bab0070bfe | dec eax $sequence_9 = { 4889442428 488d442450 48895c2458 488b4940 4c8d4aff 4c897c2450 448d4204 } // n = 7, score = 100 // 4889442428 | dec eax // 488d442450 | mov dword ptr [esp + 0x30], ebp // 48895c2458 | xor edx, edx // 488b4940 | dec eax // 4c8d4aff | mov dword ptr [esp + 0x28], ebp // 4c897c2450 | dec eax // 448d4204 | lea eax, [esp + 0xa8] condition: 7 of them and filesize < 421888 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY