SYMBOLCOMMON_NAMEaka. SYNONYMS
win.hermeticwizard (Back to overview)

HermeticWizard

VTCollection    

There is no description at this point.

References
2022-10-24 ⋅ Youtube (Virus Bulletin) ⋅ Alexander Adamov
Russian wipers in the cyberwar against Ukraine
AcidRain CaddyWiper DesertBlade DoubleZero EternalPetya HermeticWiper HermeticWizard INDUSTROYER2 IsaacWiper KillDisk PartyTicket WhisperGate
2022-04-07 ⋅ InQuest ⋅ Nick Chalard, Will MacArthur
Ukraine CyberWar Overview
CyclopsBlink Cobalt Strike GraphSteel GrimPlant HermeticWiper HermeticWizard MicroBackdoor PartyTicket Saint Bot Scieron WhisperGate
2022-03-14 ⋅ Kaspersky ⋅ GReAT
Webinar on cyberattacks in Ukraine – summary and Q&A
HermeticWiper HermeticWizard IsaacWiper PartyTicket WhisperGate
2022-03-12 ⋅ Twitter (@ET_Labs) ⋅ ET Labs
A quick thread examining the network artifacts of the HermeticWizard spreading
HermeticWizard
2022-03-10 ⋅ BrightTALK (Kaspersky GReAT) ⋅ Costin Raiu, Dan Demeter, Ivan Kwiatkowski, Kurt Baumgartner, Marco Preuss
BrightTALK: A look at current cyberattacks in Ukraine
HermeticWiper HermeticWizard IsaacWiper PartyTicket WhisperGate
2022-03-09 ⋅ Twitter (@silascutler) ⋅ Silas Cutler
Tweet on HermeticWizard's self-spreading mechanism
HermeticWizard
Yara Rules
[TLP:WHITE] win_hermeticwizard_auto (20260917 | Detects win.hermeticwizard.)
rule win_hermeticwizard_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.hermeticwizard."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hermeticwizard"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8b4508 57 8d3c8508e10110 8b0f }
            // n = 4, score = 100
            //   8b4508               | mov                 eax, dword ptr [ebp + 8]
            //   57                   | push                edi
            //   8d3c8508e10110       | lea                 edi, [eax*4 + 0x1001e108]
            //   8b0f                 | mov                 ecx, dword ptr [edi]

        $sequence_1 = { 83c30c 3b7e08 7ce6 5f 8bc6 5e 5b }
            // n = 7, score = 100
            //   83c30c               | add                 ebx, 0xc
            //   3b7e08               | cmp                 edi, dword ptr [esi + 8]
            //   7ce6                 | jl                  0xffffffe8
            //   5f                   | pop                 edi
            //   8bc6                 | mov                 eax, esi
            //   5e                   | pop                 esi
            //   5b                   | pop                 ebx

        $sequence_2 = { 3bc1 7628 8b4a14 2bc8 3b4c2420 }
            // n = 5, score = 100
            //   3bc1                 | cmp                 eax, ecx
            //   7628                 | jbe                 0x2a
            //   8b4a14               | mov                 ecx, dword ptr [edx + 0x14]
            //   2bc8                 | sub                 ecx, eax
            //   3b4c2420             | cmp                 ecx, dword ptr [esp + 0x20]

        $sequence_3 = { 66898daafeffff 59 6a5c 66898dacfeffff 59 6a63 66898daefeffff }
            // n = 7, score = 100
            //   66898daafeffff       | mov                 word ptr [ebp - 0x156], cx
            //   59                   | pop                 ecx
            //   6a5c                 | push                0x5c
            //   66898dacfeffff       | mov                 word ptr [ebp - 0x154], cx
            //   59                   | pop                 ecx
            //   6a63                 | push                0x63
            //   66898daefeffff       | mov                 word ptr [ebp - 0x152], cx

        $sequence_4 = { 7810 3de4000000 7309 8b04c5107d0110 5d c3 33c0 }
            // n = 7, score = 100
            //   7810                 | js                  0x12
            //   3de4000000           | cmp                 eax, 0xe4
            //   7309                 | jae                 0xb
            //   8b04c5107d0110       | mov                 eax, dword ptr [eax*8 + 0x10017d10]
            //   5d                   | pop                 ebp
            //   c3                   | ret                 
            //   33c0                 | xor                 eax, eax

        $sequence_5 = { 85ff 0f8428060000 8b45fc 8d55e0 53 52 }
            // n = 6, score = 100
            //   85ff                 | test                edi, edi
            //   0f8428060000         | je                  0x62e
            //   8b45fc               | mov                 eax, dword ptr [ebp - 4]
            //   8d55e0               | lea                 edx, [ebp - 0x20]
            //   53                   | push                ebx
            //   52                   | push                edx

        $sequence_6 = { ff5208 ff75ec ff15???????? 8ac3 5f eb06 }
            // n = 6, score = 100
            //   ff5208               | call                dword ptr [edx + 8]
            //   ff75ec               | push                dword ptr [ebp - 0x14]
            //   ff15????????         |                     
            //   8ac3                 | mov                 al, bl
            //   5f                   | pop                 edi
            //   eb06                 | jmp                 8

        $sequence_7 = { 8be5 5d c3 55 8bec b8bc310000 e8???????? }
            // n = 7, score = 100
            //   8be5                 | mov                 esp, ebp
            //   5d                   | pop                 ebp
            //   c3                   | ret                 
            //   55                   | push                ebp
            //   8bec                 | mov                 ebp, esp
            //   b8bc310000           | mov                 eax, 0x31bc
            //   e8????????           |                     

        $sequence_8 = { 33c0 8dbd58feffff ab ab ab }
            // n = 5, score = 100
            //   33c0                 | xor                 eax, eax
            //   8dbd58feffff         | lea                 edi, [ebp - 0x1a8]
            //   ab                   | stosd               dword ptr es:[edi], eax
            //   ab                   | stosd               dword ptr es:[edi], eax
            //   ab                   | stosd               dword ptr es:[edi], eax

        $sequence_9 = { 83e901 75f8 8d45fc c745e002000000 50 8d45dc 50 }
            // n = 7, score = 100
            //   83e901               | sub                 ecx, 1
            //   75f8                 | jne                 0xfffffffa
            //   8d45fc               | lea                 eax, [ebp - 4]
            //   c745e002000000       | mov                 dword ptr [ebp - 0x20], 2
            //   50                   | push                eax
            //   8d45dc               | lea                 eax, [ebp - 0x24]
            //   50                   | push                eax

    condition:
        7 of them and filesize < 263168
}
Download all Yara Rules