There is no description at this point.
rule win_fickle_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.fickle." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.fickle" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { c7460400000000 31c0 83c404 5e 5f 5b c3 } // n = 7, score = 100 // c7460400000000 | mov dword ptr [esi + 4], 0 // 31c0 | xor eax, eax // 83c404 | add esp, 4 // 5e | pop esi // 5f | pop edi // 5b | pop ebx // c3 | ret $sequence_1 = { bb00000000 83d3ff c1e704 01c7 c1e304 035e04 39d1 } // n = 7, score = 100 // bb00000000 | mov ebx, 0 // 83d3ff | adc ebx, -1 // c1e704 | shl edi, 4 // 01c7 | add edi, eax // c1e304 | shl ebx, 4 // 035e04 | add ebx, dword ptr [esi + 4] // 39d1 | cmp ecx, edx $sequence_2 = { c686ac00000001 8dbe080f0000 c686080f000000 897c2408 c686090f000000 8954242c f30f6f02 } // n = 7, score = 100 // c686ac00000001 | mov byte ptr [esi + 0xac], 1 // 8dbe080f0000 | lea edi, [esi + 0xf08] // c686080f000000 | mov byte ptr [esi + 0xf08], 0 // 897c2408 | mov dword ptr [esp + 8], edi // c686090f000000 | mov byte ptr [esi + 0xf09], 0 // 8954242c | mov dword ptr [esp + 0x2c], edx // f30f6f02 | movdqu xmm0, xmmword ptr [edx] $sequence_3 = { ba00000000 75b0 0fb74008 357e2c0000 f20f10442430 f20f11442420 6689442428 } // n = 7, score = 100 // ba00000000 | mov edx, 0 // 75b0 | jne 0xffffffb2 // 0fb74008 | movzx eax, word ptr [eax + 8] // 357e2c0000 | xor eax, 0x2c7e // f20f10442430 | movsd xmm0, qword ptr [esp + 0x30] // f20f11442420 | movsd qword ptr [esp + 0x20], xmm0 // 6689442428 | mov word ptr [esp + 0x28], ax $sequence_4 = { 8d8ef0120000 e8???????? e9???????? 8b07 897e30 8b4f04 c786b834000001000000 } // n = 7, score = 100 // 8d8ef0120000 | lea ecx, [esi + 0x12f0] // e8???????? | // e9???????? | // 8b07 | mov eax, dword ptr [edi] // 897e30 | mov dword ptr [esi + 0x30], edi // 8b4f04 | mov ecx, dword ptr [edi + 4] // c786b834000001000000 | mov dword ptr [esi + 0x34b8], 1 $sequence_5 = { e8???????? c7460c00000080 84db 750e f0ff0e 7509 89f1 } // n = 7, score = 100 // e8???????? | // c7460c00000080 | mov dword ptr [esi + 0xc], 0x80000000 // 84db | test bl, bl // 750e | jne 0x10 // f0ff0e | lock dec dword ptr [esi] // 7509 | jne 0xb // 89f1 | mov ecx, esi $sequence_6 = { c70600000000 c6460401 e9???????? 8b4910 85c9 0f8409030000 8b14854c9a8901 } // n = 7, score = 100 // c70600000000 | mov dword ptr [esi], 0 // c6460401 | mov byte ptr [esi + 4], 1 // e9???????? | // 8b4910 | mov ecx, dword ptr [ecx + 0x10] // 85c9 | test ecx, ecx // 0f8409030000 | je 0x30f // 8b14854c9a8901 | mov edx, dword ptr [eax*4 + 0x1899a4c] $sequence_7 = { a1???????? 85c0 7403 56 ffd0 84db 0f848c000000 } // n = 7, score = 100 // a1???????? | // 85c0 | test eax, eax // 7403 | je 5 // 56 | push esi // ffd0 | call eax // 84db | test bl, bl // 0f848c000000 | je 0x92 $sequence_8 = { e9???????? 81c370ffffff be90000000 56 53 ff742420 } // n = 6, score = 100 // e9???????? | // 81c370ffffff | add ebx, 0xffffff70 // be90000000 | mov esi, 0x90 // 56 | push esi // 53 | push ebx // ff742420 | push dword ptr [esp + 0x20] $sequence_9 = { c144243007 037c2440 014c2418 035c2430 036c2444 8b4c2404 31e9 } // n = 7, score = 100 // c144243007 | rol dword ptr [esp + 0x30], 7 // 037c2440 | add edi, dword ptr [esp + 0x40] // 014c2418 | add dword ptr [esp + 0x18], ecx // 035c2430 | add ebx, dword ptr [esp + 0x30] // 036c2444 | add ebp, dword ptr [esp + 0x44] // 8b4c2404 | mov ecx, dword ptr [esp + 4] // 31e9 | xor ecx, ebp condition: 7 of them and filesize < 1646592 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY