SYMBOLCOMMON_NAMEaka. SYNONYMS
win.elirks (Back to overview)

Elirks

VTCollection    

Elirks is a basic backdoor Trojan, first discovered in 2010, that is primarily used to steal information from compromised systems. Mostly attacks using Elirks occurring in East Asia. One of the unique features of the malware is that it retrieves its C2 address by accessing a pre-determined microblog service or SNS. Attackers create accounts on those services and post encoded IP addresses or the domain names of real C2 servers in advance of distributing the backdoor. Multiple Elirks variants using Japanese blog services for the last couple of years.

References
2016-09-15 ⋅ Palo Alto Networks Unit 42 ⋅ Kaoru Hayashi
MILE TEA: Cyber Espionage Campaign Targets Asia Pacific Businesses and Government Agencies
Elirks Logedrut Micrass
2016-06-23 ⋅ Palo Alto Networks Unit 42 ⋅ Kaoru Hayashi
Tracking Elirks Variants in Japan: Similarities to Previous Attacks
Elirks
Yara Rules
[TLP:WHITE] win_elirks_auto (20260917 | Detects win.elirks.)
rule win_elirks_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.elirks."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.elirks"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8d4c2414 51 6800040000 8d942420030000 52 8d442424 50 }
            // n = 7, score = 100
            //   8d4c2414             | lea                 ecx, [esp + 0x14]
            //   51                   | push                ecx
            //   6800040000           | push                0x400
            //   8d942420030000       | lea                 edx, [esp + 0x320]
            //   52                   | push                edx
            //   8d442424             | lea                 eax, [esp + 0x24]
            //   50                   | push                eax

        $sequence_1 = { 50 6a04 8d4c2420 51 56 e8???????? 85c0 }
            // n = 7, score = 100
            //   50                   | push                eax
            //   6a04                 | push                4
            //   8d4c2420             | lea                 ecx, [esp + 0x20]
            //   51                   | push                ecx
            //   56                   | push                esi
            //   e8????????           |                     
            //   85c0                 | test                eax, eax

        $sequence_2 = { 33db 55 895c2414 ff15???????? 8b3d???????? }
            // n = 5, score = 100
            //   33db                 | xor                 ebx, ebx
            //   55                   | push                ebp
            //   895c2414             | mov                 dword ptr [esp + 0x14], ebx
            //   ff15????????         |                     
            //   8b3d????????         |                     

        $sequence_3 = { b818400000 e8???????? 8b84241c400000 8b8858010000 8b9054010000 53 56 }
            // n = 7, score = 100
            //   b818400000           | mov                 eax, 0x4018
            //   e8????????           |                     
            //   8b84241c400000       | mov                 eax, dword ptr [esp + 0x401c]
            //   8b8858010000         | mov                 ecx, dword ptr [eax + 0x158]
            //   8b9054010000         | mov                 edx, dword ptr [eax + 0x154]
            //   53                   | push                ebx
            //   56                   | push                esi

        $sequence_4 = { 53 55 8bd8 a1???????? 56 89442418 a1???????? }
            // n = 7, score = 100
            //   53                   | push                ebx
            //   55                   | push                ebp
            //   8bd8                 | mov                 ebx, eax
            //   a1????????           |                     
            //   56                   | push                esi
            //   89442418             | mov                 dword ptr [esp + 0x18], eax
            //   a1????????           |                     

        $sequence_5 = { 0f84d3030000 8b442438 3b44242c 7f12 8d742410 e8???????? }
            // n = 6, score = 100
            //   0f84d3030000         | je                  0x3d9
            //   8b442438             | mov                 eax, dword ptr [esp + 0x38]
            //   3b44242c             | cmp                 eax, dword ptr [esp + 0x2c]
            //   7f12                 | jg                  0x14
            //   8d742410             | lea                 esi, [esp + 0x10]
            //   e8????????           |                     

        $sequence_6 = { be16000000 8da42400000000 0fb70c02 6683f940 7405 668908 eb05 }
            // n = 7, score = 100
            //   be16000000           | mov                 esi, 0x16
            //   8da42400000000       | lea                 esp, [esp]
            //   0fb70c02             | movzx               ecx, word ptr [edx + eax]
            //   6683f940             | cmp                 cx, 0x40
            //   7405                 | je                  7
            //   668908               | mov                 word ptr [eax], cx
            //   eb05                 | jmp                 7

        $sequence_7 = { 668911 0fb65e01 0fb65602 83e30f 03db c1ea06 83c102 }
            // n = 7, score = 100
            //   668911               | mov                 word ptr [ecx], dx
            //   0fb65e01             | movzx               ebx, byte ptr [esi + 1]
            //   0fb65602             | movzx               edx, byte ptr [esi + 2]
            //   83e30f               | and                 ebx, 0xf
            //   03db                 | add                 ebx, ebx
            //   c1ea06               | shr                 edx, 6
            //   83c102               | add                 ecx, 2

        $sequence_8 = { 7433 83f808 7f45 8d442408 6a0c }
            // n = 5, score = 100
            //   7433                 | je                  0x35
            //   83f808               | cmp                 eax, 8
            //   7f45                 | jg                  0x47
            //   8d442408             | lea                 eax, [esp + 8]
            //   6a0c                 | push                0xc

        $sequence_9 = { 83c408 85f6 741e 83c61e 56 ff15???????? }
            // n = 6, score = 100
            //   83c408               | add                 esp, 8
            //   85f6                 | test                esi, esi
            //   741e                 | je                  0x20
            //   83c61e               | add                 esi, 0x1e
            //   56                   | push                esi
            //   ff15????????         |                     

    condition:
        7 of them and filesize < 81920
}
Download all Yara Rules