Actor(s): DragonOK, Samurai Panda
There is no description at this point.
rule win_former_first_rat_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.former_first_rat." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.former_first_rat" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 57 e8???????? 83c404 56 e8???????? 8b8504ffffff 83c404 } // n = 7, score = 200 // 57 | push edi // e8???????? | // 83c404 | add esp, 4 // 56 | push esi // e8???????? | // 8b8504ffffff | mov eax, dword ptr [ebp - 0xfc] // 83c404 | add esp, 4 $sequence_1 = { 8d8de0feffff 51 bb08000000 e8???????? 8b9df8feffff 57 e8???????? } // n = 7, score = 200 // 8d8de0feffff | lea ecx, [ebp - 0x120] // 51 | push ecx // bb08000000 | mov ebx, 8 // e8???????? | // 8b9df8feffff | mov ebx, dword ptr [ebp - 0x108] // 57 | push edi // e8???????? | $sequence_2 = { 75f8 8d85b4feffff 68???????? b90d000000 be???????? 50 } // n = 6, score = 200 // 75f8 | jne 0xfffffffa // 8d85b4feffff | lea eax, [ebp - 0x14c] // 68???????? | // b90d000000 | mov ecx, 0xd // be???????? | // 50 | push eax $sequence_3 = { 740a c705????????05000000 6a59 ffd6 } // n = 4, score = 200 // 740a | je 0xc // c705????????05000000 | // 6a59 | push 0x59 // ffd6 | call esi $sequence_4 = { 81c208020000 f3a5 3b44240c 75e4 } // n = 4, score = 200 // 81c208020000 | add edx, 0x208 // f3a5 | rep movsd dword ptr es:[edi], dword ptr [esi] // 3b44240c | cmp eax, dword ptr [esp + 0xc] // 75e4 | jne 0xffffffe6 $sequence_5 = { 8d85f4efffff 6a00 50 e8???????? 8b85e4eeffff 83c40c } // n = 6, score = 200 // 8d85f4efffff | lea eax, [ebp - 0x100c] // 6a00 | push 0 // 50 | push eax // e8???????? | // 8b85e4eeffff | mov eax, dword ptr [ebp - 0x111c] // 83c40c | add esp, 0xc $sequence_6 = { 2bf1 b87fe0077e f7ee c1fa08 8bf2 } // n = 5, score = 200 // 2bf1 | sub esi, ecx // b87fe0077e | mov eax, 0x7e07e07f // f7ee | imul esi // c1fa08 | sar edx, 8 // 8bf2 | mov esi, edx $sequence_7 = { b93c000000 03ce 83c40c c74424241c000000 81f900100000 7e5a } // n = 6, score = 200 // b93c000000 | mov ecx, 0x3c // 03ce | add ecx, esi // 83c40c | add esp, 0xc // c74424241c000000 | mov dword ptr [esp + 0x24], 0x1c // 81f900100000 | cmp ecx, 0x1000 // 7e5a | jle 0x5c $sequence_8 = { 02c8 488d05f0f60100 02c9 4002ce } // n = 4, score = 100 // 02c8 | mov eax, dword ptr [ecx + 0x10] // 488d05f0f60100 | cmp dword ptr [eax + 0x94], 0 // 02c9 | add cl, al // 4002ce | dec eax $sequence_9 = { 03c1 89442468 413bc5 7250 } // n = 4, score = 100 // 03c1 | inc ecx // 89442468 | movzx ecx, dl // 413bc5 | inc edx // 7250 | xor dl, byte ptr [ecx + eax] $sequence_10 = { 03cd 8908 f6437804 7417 } // n = 4, score = 100 // 03cd | inc ebx // 8908 | lea eax, [ebp + ebp] // f6437804 | inc esp // 7417 | mov ebp, eax $sequence_11 = { 03cf 8908 488b4340 48833800 } // n = 4, score = 100 // 03cf | movzx ecx, cl // 8908 | inc edx // 488b4340 | mov dl, byte ptr [ecx + eax] // 48833800 | inc ecx $sequence_12 = { 017130 83793005 7407 33c0 } // n = 4, score = 100 // 017130 | add dword ptr [ecx + 0x30], esi // 83793005 | cmp dword ptr [ecx + 0x30], 5 // 7407 | je 9 // 33c0 | xor eax, eax $sequence_13 = { 02ca 4402d1 410fb6ca 42321401 } // n = 4, score = 100 // 02ca | dec eax // 4402d1 | cmp edi, eax // 410fb6ca | add cl, al // 42321401 | dec eax $sequence_14 = { 03ca 0fb6c9 428a1401 4130143b } // n = 4, score = 100 // 03ca | mov byte ptr [ebx], dl // 0fb6c9 | inc edx // 428a1401 | xor byte ptr [ecx + eax], dl // 4130143b | inc edx $sequence_15 = { 03d0 69d290010000 3bca 740a 418b84b308360400 } // n = 5, score = 100 // 03d0 | xor byte ptr [ebx + edi], dl // 69d290010000 | dec ecx // 3bca | inc ebx // 740a | dec esp // 418b84b308360400 | cmp ebx, ebx condition: 7 of them and filesize < 626688 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY