Actor(s): Lazarus Group
There is no description at this point.
rule win_ghost_secret_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.ghost_secret." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ghost_secret" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { c68424ec00000028 c68424ed00000027 c68424ee0000002f c68424ef0000004d c68424f000000014 c68424f100000036 c68424f20000009f } // n = 7, score = 200 // c68424ec00000028 | mov byte ptr [esp + 0xec], 0x28 // c68424ed00000027 | mov byte ptr [esp + 0xed], 0x27 // c68424ee0000002f | mov byte ptr [esp + 0xee], 0x2f // c68424ef0000004d | mov byte ptr [esp + 0xef], 0x4d // c68424f000000014 | mov byte ptr [esp + 0xf0], 0x14 // c68424f100000036 | mov byte ptr [esp + 0xf1], 0x36 // c68424f20000009f | mov byte ptr [esp + 0xf2], 0x9f $sequence_1 = { c684246001000016 c684246101000032 c68424620100002e 8884248e020000 b024 b333 b17c } // n = 7, score = 200 // c684246001000016 | mov byte ptr [esp + 0x160], 0x16 // c684246101000032 | mov byte ptr [esp + 0x161], 0x32 // c68424620100002e | mov byte ptr [esp + 0x162], 0x2e // 8884248e020000 | mov byte ptr [esp + 0x28e], al // b024 | mov al, 0x24 // b333 | mov bl, 0x33 // b17c | mov cl, 0x7c $sequence_2 = { c68424df030000b7 c68424e003000072 c68424e1030000cc c68424e2030000e4 c684243c01000005 8884243d010000 c684243e0100002d } // n = 7, score = 200 // c68424df030000b7 | mov byte ptr [esp + 0x3df], 0xb7 // c68424e003000072 | mov byte ptr [esp + 0x3e0], 0x72 // c68424e1030000cc | mov byte ptr [esp + 0x3e1], 0xcc // c68424e2030000e4 | mov byte ptr [esp + 0x3e2], 0xe4 // c684243c01000005 | mov byte ptr [esp + 0x13c], 5 // 8884243d010000 | mov byte ptr [esp + 0x13d], al // c684243e0100002d | mov byte ptr [esp + 0x13e], 0x2d $sequence_3 = { 8d8424dc040000 6a11 50 e8???????? 83c408 50 } // n = 6, score = 200 // 8d8424dc040000 | lea eax, [esp + 0x4dc] // 6a11 | push 0x11 // 50 | push eax // e8???????? | // 83c408 | add esp, 8 // 50 | push eax $sequence_4 = { 8d542448 52 e8???????? 8d744604 8d8424b80a0000 50 e8???????? } // n = 7, score = 200 // 8d542448 | lea edx, [esp + 0x48] // 52 | push edx // e8???????? | // 8d744604 | lea esi, [esi + eax*2 + 4] // 8d8424b80a0000 | lea eax, [esp + 0xab8] // 50 | push eax // e8???????? | $sequence_5 = { ff15???????? 85c0 740b 33c0 5f 5e 5b } // n = 7, score = 200 // ff15???????? | // 85c0 | test eax, eax // 740b | je 0xd // 33c0 | xor eax, eax // 5f | pop edi // 5e | pop esi // 5b | pop ebx $sequence_6 = { 6a01 8bf9 6a02 ff15???????? 8bf0 83feff 750d } // n = 7, score = 200 // 6a01 | push 1 // 8bf9 | mov edi, ecx // 6a02 | push 2 // ff15???????? | // 8bf0 | mov esi, eax // 83feff | cmp esi, -1 // 750d | jne 0xf $sequence_7 = { 56 ff15???????? 8d94243c010000 6a0c 52 a3???????? e8???????? } // n = 7, score = 200 // 56 | push esi // ff15???????? | // 8d94243c010000 | lea edx, [esp + 0x13c] // 6a0c | push 0xc // 52 | push edx // a3???????? | // e8???????? | $sequence_8 = { c684247903000043 c684247a03000087 c684247b0300005c c684247c03000090 c684247d0300002a c684247e03000040 c684247f030000a0 } // n = 7, score = 200 // c684247903000043 | mov byte ptr [esp + 0x379], 0x43 // c684247a03000087 | mov byte ptr [esp + 0x37a], 0x87 // c684247b0300005c | mov byte ptr [esp + 0x37b], 0x5c // c684247c03000090 | mov byte ptr [esp + 0x37c], 0x90 // c684247d0300002a | mov byte ptr [esp + 0x37d], 0x2a // c684247e03000040 | mov byte ptr [esp + 0x37e], 0x40 // c684247f030000a0 | mov byte ptr [esp + 0x37f], 0xa0 $sequence_9 = { c784243c20000000000000 99 f7fe 66c74424140200 8d0452 d1e0 } // n = 6, score = 200 // c784243c20000000000000 | mov dword ptr [esp + 0x203c], 0 // 99 | cdq // f7fe | idiv esi // 66c74424140200 | mov word ptr [esp + 0x14], 2 // 8d0452 | lea eax, [edx + edx*2] // d1e0 | shl eax, 1 condition: 7 of them and filesize < 278528 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY