Actor(s): APT29
A stager used by APT29 to deploy CobaltStrike.
rule win_halfrig_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.halfrig." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.halfrig" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 75c0 430fb6041a 4138041a 0f84a5040000 418b0424 3905???????? 7e48 } // n = 7, score = 100 // 75c0 | dec eax // 430fb6041a | lea ecx, [0x7c968] // 4138041a | mov byte ptr [edx], al // 0f84a5040000 | dec eax // 418b0424 | lea edx, [esp + 0x20] // 3905???????? | // 7e48 | dec eax $sequence_1 = { 8802 488d9530030000 e8???????? 488d0dddd30600 e8???????? 33ff 48bb0b9109194dfd9bf3 } // n = 7, score = 100 // 8802 | lea ecx, [0x49d62] // 488d9530030000 | je 0xeff // e8???????? | // 488d0dddd30600 | dec esp // e8???????? | // 33ff | lea eax, [0x48b34] // 48bb0b9109194dfd9bf3 | dec esp $sequence_2 = { 488d0d4c3a0700 e8???????? 40383d???????? 7435 488bd3 4c8bc7 43301438 } // n = 7, score = 100 // 488d0d4c3a0700 | dec ecx // e8???????? | // 40383d???????? | // 7435 | cmp eax, 0x401 // 488bd3 | jb 0x4a7 // 4c8bc7 | dec eax // 43301438 | lea ecx, [ebp + 0x330] $sequence_3 = { 8802 488d542420 e8???????? 488d0d20bd0700 e8???????? 40383d???????? 7435 } // n = 7, score = 100 // 8802 | dec eax // 488d542420 | lea ebx, [0x42b5f] // e8???????? | // 488d0d20bd0700 | dec eax // e8???????? | // 40383d???????? | // 7435 | lea edi, [0x42b58] $sequence_4 = { 4883ea01 75ad 488b5370 488bcb e8???????? ba04010000 488d8b80010000 } // n = 7, score = 100 // 4883ea01 | dec eax // 75ad | lea ecx, [ecx + 0x80] // 488b5370 | movups xmm0, xmmword ptr [eax] // 488bcb | dec eax // e8???????? | // ba04010000 | lea ecx, [ebp + 0x330] // 488d8b80010000 | dec eax $sequence_5 = { 488dac24c0f8ffff 4881ec40080000 be08000000 488d4c2420 8bd6 488d055a500400 66660f1f840000000000 } // n = 7, score = 100 // 488dac24c0f8ffff | lea eax, [0x4319c] // 4881ec40080000 | dec eax // be08000000 | mov edx, esi // 488d4c2420 | nop word ptr [eax + eax] // 8bd6 | dec eax // 488d055a500400 | lea ecx, [ecx + 0x80] // 66660f1f840000000000 | dec eax $sequence_6 = { 488d0d3fb30800 e8???????? 833d????????ff 0f858a000000 488d542420 4c8bc6 488d8530030000 } // n = 7, score = 100 // 488d0d3fb30800 | jb 0x320 // e8???????? | // 833d????????ff | // 0f858a000000 | dec eax // 488d542420 | lea ecx, [ebp + 0x330] // 4c8bc6 | dec eax // 488d8530030000 | lea eax, [0x2f16c] $sequence_7 = { 40883d???????? 4c893d???????? 488d8d30030000 488d058c2e0400 488bd6 660f1f840000000000 488d8980000000 } // n = 7, score = 100 // 40883d???????? | // 4c893d???????? | // 488d8d30030000 | movups xmm0, xmmword ptr [eax] // 488d058c2e0400 | movups xmm1, xmmword ptr [eax + 0x10] // 488bd6 | dec eax // 660f1f840000000000 | lea eax, [0x452aa] // 488d8980000000 | nop word ptr [eax + eax] $sequence_8 = { 488d0d277a0400 c705????????679f9b01 c705????????6990e984 c705????????3d6d27f5 e8???????? 403835???????? 4c8d0d0e7b0400 } // n = 7, score = 100 // 488d0d277a0400 | jb 0x1ed0 // c705????????679f9b01 | // c705????????6990e984 | // c705????????3d6d27f5 | // e8???????? | // 403835???????? | // 4c8d0d0e7b0400 | dec eax $sequence_9 = { 408835???????? 418b06 4c898b30030000 4088b338030000 3905???????? 7e3f 488d0d38820400 } // n = 7, score = 100 // 408835???????? | // 418b06 | movups xmm0, xmmword ptr [eax] // 4c898b30030000 | movups xmm1, xmmword ptr [eax + 0x10] // 4088b338030000 | dec eax // 3905???????? | // 7e3f | lea eax, [0x43e4c] // 488d0d38820400 | dec eax condition: 7 of them and filesize < 1369088 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY