SYMBOLCOMMON_NAMEaka. SYNONYMS
win.firechili (Back to overview)

Fire Chili

Actor(s): Shell Crew

VTCollection    

The purpose of this rootkit/driver is hiding and protecting malicious artifacts from user-mode components(e.g. files, processes, registry keys and network connections).
According to Fortguard Labs, this malware uses Direct Kernel Object Modification (DKOM), which involves undocumented kernel structures and objects, for its operations, why this malware has to rely on specific OS builds.

References
2022-04-01 ⋅ The Hacker News ⋅ Ravie Lakshmanan
Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit
Fire Chili Ghost RAT
2022-03-30 ⋅ Fortinet ⋅ Eliran Voronovitch, Rotem Sde-Or
New Milestones for Deep Panda: Log4Shell and Digitally Signed Fire Chili Rootkits
Fire Chili Ghost RAT
Yara Rules
[TLP:WHITE] win_firechili_auto (20260917 | Detects win.firechili.)
rule win_firechili_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.firechili."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.firechili"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 0f8824020000 488b5a70 4885db 0f8410020000 4084f6 7405 8b4b18 }
            // n = 7, score = 100
            //   0f8824020000         | lea                 ecx, [esp + 0x50]
            //   488b5a70             | dec                 eax
            //   4885db               | mov                 dword ptr [esp + 0x30], ecx
            //   0f8410020000         | inc                 ebp
            //   4084f6               | xor                 eax, eax
            //   7405                 | mov                 byte ptr [esp + 0x28], dl
            //   8b4b18               | dec                 eax

        $sequence_1 = { 4533f6 4c89742438 4c89742430 f6c204 7407 33c0 }
            // n = 6, score = 100
            //   4533f6               | lea                 ecx, [0x2d0c]
            //   4c89742438           | jb                  0x136f
            //   4c89742430           | dec                 eax
            //   f6c204               | lea                 ecx, [0x5910]
            //   7407                 | dec                 eax
            //   33c0                 | lea                 ecx, [0x5894]

        $sequence_2 = { 85c0 782b 488b4c2468 4885c9 7421 488b4908 4885c9 }
            // n = 7, score = 100
            //   85c0                 | test                eax, eax
            //   782b                 | js                  0x3b7
            //   488b4c2468           | dec                 eax
            //   4885c9               | mov                 esi, dword ptr [esp + 0x28]
            //   7421                 | je                  0x305
            //   488b4908             | dec                 eax
            //   4885c9               | cmp                 eax, ebx

        $sequence_3 = { 0f57c0 4889bc2488000000 33ff c7450730000000 ba3f000f00 }
            // n = 5, score = 100
            //   0f57c0               | test                esi, esi
            //   4889bc2488000000     | je                  0x1d18
            //   33ff                 | dec                 eax
            //   c7450730000000       | mov                 ecx, eax
            //   ba3f000f00           | dec                 ebp

        $sequence_4 = { 440fb701 4533d2 488bda 488bf1 418bea 458bca 418bfa }
            // n = 7, score = 100
            //   440fb701             | dec                 eax
            //   4533d2               | sub                 esp, 0x30
            //   488bda               | dec                 esp
            //   488bf1               | mov                 eax, dword ptr [edx + 8]
            //   418bea               | xor                 ebx, ebx
            //   458bca               | dec                 eax
            //   418bfa               | mov                 dword ptr [esp + 0x20], ebx

        $sequence_5 = { 75dc eb05 4885d2 7511 }
            // n = 4, score = 100
            //   75dc                 | dec                 eax
            //   eb05                 | test                edx, edx
            //   4885d2               | dec                 eax
            //   7511                 | mov                 esi, ecx

        $sequence_6 = { 418bc6 81c200040000 4a393400 740c ffc1 48ffc0 483bc2 }
            // n = 7, score = 100
            //   418bc6               | test                ecx, ecx
            //   81c200040000         | je                  0xd84
            //   4a393400             | push                ebx
            //   740c                 | dec                 eax
            //   ffc1                 | sub                 esp, 0x20
            //   48ffc0               | dec                 eax
            //   483bc2               | add                 esp, 0x30

        $sequence_7 = { 4883ea01 75e1 eb05 4885d2 750a 4883e902 41b905000080 }
            // n = 7, score = 100
            //   4883ea01             | mov                 dword ptr [edx], eax
            //   75e1                 | dec                 eax
            //   eb05                 | mov                 dword ptr [edx + 8], eax
            //   4885d2               | dec                 eax
            //   750a                 | mov                 dword ptr [edx + 0x10], eax
            //   4883e902             | dec                 eax
            //   41b905000080         | mov                 dword ptr [edx + 0x18], eax

        $sequence_8 = { 4c8d442440 c644242800 488bcb c744242000000000 418d51fe ff15???????? 85c0 }
            // n = 7, score = 100
            //   4c8d442440           | shr                 edx, 1
            //   c644242800           | jmp                 0xb9
            //   488bcb               | mov                 eax, 0xc000000d
            //   c744242000000000     | test                eax, eax
            //   418d51fe             | js                  0x10d
            //   ff15????????         |                     
            //   85c0                 | dec                 eax

        $sequence_9 = { 83e801 7454 83e801 7419 83f801 0f85e1000000 }
            // n = 6, score = 100
            //   83e801               | lea                 ecx, [0x4238]
            //   7454                 | dec                 eax
            //   83e801               | mov                 edx, dword ptr [esp + 0x28]
            //   7419                 | dec                 eax
            //   83f801               | lea                 ecx, [0x2fbe]
            //   0f85e1000000         | dec                 eax

    condition:
        7 of them and filesize < 91136
}
Download all Yara Rules