SYMBOLCOMMON_NAMEaka. SYNONYMS
win.ghostemperor (Back to overview)

GhostEmperor

VTCollection    

There is no description at this point.

References
2024-07-17 ⋅ SYGNIA ⋅ Dor Nizar
The Return of Ghost Emperor’s Demodex
GhostEmperor GhostEmperor
2021-09-30 ⋅ Kaspersky ⋅ Aseel Kayal, Mark Lechtik, Paul Rascagnères, Vasily Berdnikov
GhostEmperor: From ProxyLogon to kernel mode
GhostEmperor GhostEmperor
2021-09-30 ⋅ Kaspersky Labs ⋅ Kaspersky Labs
GhostEmperor’s infection chain and post-exploitation toolset: technical detail
GhostEmperor GhostEmperor
2021-07-29 ⋅ Kaspersky ⋅ Kaspersky
GhostEmperor: Chinese-speaking APT targets high-profile victims using unknown rootkit
GhostEmperor
Yara Rules
[TLP:WHITE] win_ghostemperor_auto (20260917 | Detects win.ghostemperor.)
rule win_ghostemperor_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.ghostemperor."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ghostemperor"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { e8???????? 4885c0 7450 4989c4 448b4650 44034648 49c1e003 }
            // n = 7, score = 200
            //   e8????????           |                     
            //   4885c0               | add                 ebx, ecx
            //   7450                 | add                 ecx, edx
            //   4989c4               | mov                 edx, ecx
            //   448b4650             | shl                 edx, 5
            //   44034648             | mov                 ebx, ecx
            //   49c1e003             | sub                 ebx, edx

        $sequence_1 = { 740d e8???????? 48c7464000000000 48895e40 8b4648 }
            // n = 5, score = 200
            //   740d                 | xor                 eax, 0x7b8803ae
            //   e8????????           |                     
            //   48c7464000000000     | add                 eax, 0x4d38f052
            //   48895e40             | xor                 eax, 0x877f258e
            //   8b4648               | mov                 dword ptr [ebp + 0x30], eax

        $sequence_2 = { 8b4e50 29c2 8d1c09 39da 7c5f }
            // n = 5, score = 200
            //   8b4e50               | mov                 dword ptr [ebp - 0xc], eax
            //   29c2                 | dec                 eax
            //   8d1c09               | mov                 eax, dword ptr [ebp + 0x10]
            //   39da                 | add                 eax, 0x4fa9727
            //   7c5f                 | xor                 eax, 0x65a63713

        $sequence_3 = { 488b5640 448b4648 49c1e003 4c89e1 e8???????? }
            // n = 5, score = 200
            //   488b5640             | mov                 dword ptr [ebp - 0xc], eax
            //   448b4648             | dec                 eax
            //   49c1e003             | mov                 eax, dword ptr [ebp + 0x10]
            //   4c89e1               | mov                 eax, dword ptr [eax + 0x4c]
            //   e8????????           |                     

        $sequence_4 = { 4889c1 4889ea 4989d8 e8???????? eb07 }
            // n = 5, score = 200
            //   4889c1               | add                 eax, 0x4fa9727
            //   4889ea               | xor                 eax, 0x65a63713
            //   4989d8               | mov                 dword ptr [ebp - 0xc], eax
            //   e8????????           |                     
            //   eb07                 | dec                 eax

        $sequence_5 = { 4883c2e0 4883c604 39f1 75ce }
            // n = 4, score = 200
            //   4883c2e0             | add                 ebx, ecx
            //   4883c604             | add                 ebx, eax
            //   39f1                 | add                 eax, 0x4fa9727
            //   75ce                 | xor                 eax, 0x65a63713

        $sequence_6 = { 0f104cfa10 0f1014f9 0f57d0 0f1044f910 }
            // n = 4, score = 200
            //   0f104cfa10           | mov                 eax, dword ptr [ebp + 0x10]
            //   0f1014f9             | mov                 eax, dword ptr [eax + 0x4c]
            //   0f57d0               | rol                 eax, 5
            //   0f1044f910           | add                 eax, 0x4fa9727

        $sequence_7 = { 49c1e003 488d5108 e8???????? 8b4648 85c0 746e 8b564c }
            // n = 7, score = 200
            //   49c1e003             | xor                 eax, 0x65a63713
            //   488d5108             | mov                 dword ptr [ebp - 0xc], eax
            //   e8????????           |                     
            //   8b4648               | dec                 eax
            //   85c0                 | mov                 eax, dword ptr [ebp + 0x10]
            //   746e                 | mov                 eax, dword ptr [eax + 0x4c]
            //   8b564c               | rol                 eax, 5

        $sequence_8 = { 48897c2448 448bc5 89442440 498bd6 }
            // n = 4, score = 100
            //   48897c2448           | movzx               eax, word ptr [ebp + ecx - 0x29]
            //   448bc5               | mov                 word ptr [ebp + ecx + 0x17], ax
            //   89442440             | dec                 eax
            //   498bd6               | mov                 dword ptr [esp + 0x48], edi

        $sequence_9 = { 00c2 488b8568020000 8854080c 488b85b0020000 }
            // n = 4, score = 100
            //   00c2                 | add                 cl, al
            //   488b8568020000       | dec                 eax
            //   8854080c             | mov                 eax, dword ptr [ebp + 0x268]
            //   488b85b0020000       | dec                 eax

        $sequence_10 = { 052797fa04 351337a665 8945f4 488b4510 }
            // n = 4, score = 100
            //   052797fa04           | dec                 eax
            //   351337a665           | sub                 esp, 0x20
            //   8945f4               | add                 ebx, eax
            //   488b4510             | imul                ecx, ebx, 0x3e8

        $sequence_11 = { 0fb78316010000 c1e208 0bd1 0fb6c8 }
            // n = 4, score = 100
            //   0fb78316010000       | jb                  0xfffffff2
            //   c1e208               | jmp                 0x22
            //   0bd1                 | dec                 eax
            //   0fb6c8               | test                eax, eax

        $sequence_12 = { 05f226dac9 35bcfe1eea 894534 488b4550 }
            // n = 4, score = 100
            //   05f226dac9           | inc                 ecx
            //   35bcfe1eea           | call                esi
            //   894534               | add                 ebx, ecx
            //   488b4550             | add                 ebx, eax

        $sequence_13 = { 00c1 488b8568020000 488b95b0020000 884c100c }
            // n = 4, score = 100
            //   00c1                 | movzx               eax, word ptr [ebx + 0x116]
            //   488b8568020000       | shl                 edx, 8
            //   488b95b0020000       | or                  edx, ecx
            //   884c100c             | movzx               ecx, al

        $sequence_14 = { 7567 8b542450 33c9 ff15???????? 488bf8 }
            // n = 5, score = 100
            //   7567                 | mov                 edx, esi
            //   8b542450             | mov                 esi, eax
            //   33c9                 | test                eax, eax
            //   ff15????????         |                     
            //   488bf8               | jns                 0x30

        $sequence_15 = { 01c1 89ca c1ea1f c1f904 }
            // n = 4, score = 100
            //   01c1                 | mov                 eax, ecx
            //   89ca                 | add                 dl, al
            //   c1ea1f               | dec                 eax
            //   c1f904               | mov                 eax, dword ptr [ebp + 0x268]

        $sequence_16 = { 4983f90f 72bf 66895df5 c745f701000000 488bcb 0fb7440dd7 6689440d17 }
            // n = 7, score = 100
            //   4983f90f             | dec                 ecx
            //   72bf                 | cmp                 ecx, 0xf
            //   66895df5             | jb                  0xffffffc1
            //   c745f701000000       | mov                 word ptr [ebp - 0xb], bx
            //   488bcb               | mov                 dword ptr [ebp - 9], 1
            //   0fb7440dd7           | dec                 eax
            //   6689440d17           | mov                 ecx, ebx

        $sequence_17 = { 01c3 69cbe8030000 81c130750000 4883ec20 }
            // n = 4, score = 100
            //   01c3                 | add                 eax, 2
            //   69cbe8030000         | dec                 eax
            //   81c130750000         | mov                 dword ptr [ebp + 0xc8], eax
            //   4883ec20             | add                 dl, al

        $sequence_18 = { 8bf0 85c0 792e 4c8d442470 }
            // n = 4, score = 100
            //   8bf0                 | inc                 esp
            //   85c0                 | mov                 eax, ebp
            //   792e                 | mov                 dword ptr [esp + 0x40], eax
            //   4c8d442470           | dec                 ecx

        $sequence_19 = { ffc0 4881c200010000 413bc0 72ed eb1b }
            // n = 5, score = 100
            //   ffc0                 | dec                 esp
            //   4881c200010000       | lea                 eax, [esp + 0x70]
            //   413bc0               | jne                 0x69
            //   72ed                 | mov                 edx, dword ptr [esp + 0x50]
            //   eb1b                 | xor                 ecx, ecx

        $sequence_20 = { c7858c000000bf00d200 0f108580000000 c78590000000f0000000 8b8590000000 }
            // n = 4, score = 100
            //   c7858c000000bf00d200     | je    0xa
            //   0f108580000000       | dec                 ecx
            //   c78590000000f0000000     | cmp    eax, eax
            //   8b8590000000         | jne                 0x3d

        $sequence_21 = { 4885c0 7405 493bc0 7538 0f31 48c1e220 488d0db130ffff }
            // n = 7, score = 100
            //   4885c0               | dec                 eax
            //   7405                 | mov                 edi, eax
            //   493bc0               | inc                 eax
            //   7538                 | dec                 eax
            //   0f31                 | add                 edx, 0x100
            //   48c1e220             | inc                 ecx
            //   488d0db130ffff       | cmp                 eax, eax

        $sequence_22 = { 01d1 89ca c1e205 89cb }
            // n = 4, score = 100
            //   01d1                 | sar                 ecx, 4
            //   89ca                 | add                 ecx, eax
            //   c1e205               | mov                 edx, ecx
            //   89cb                 | shr                 edx, 0x1f

        $sequence_23 = { 0552f0384d 358e257f87 894530 488b4570 }
            // n = 4, score = 100
            //   0552f0384d           | sub                 esp, 0x20
            //   358e257f87           | inc                 ecx
            //   894530               | call                esi
            //   488b4570             | dec                 eax

    condition:
        7 of them and filesize < 1115136
}
Download all Yara Rules