There is no description at this point.
rule win_holerun_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.holerun." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.holerun" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 488b45f8 48f7d0 488905???????? 4883c440 5d } // n = 5, score = 100 // 488b45f8 | mov ecx, eax // 48f7d0 | call eax // 488905???????? | // 4883c440 | mov eax, dword ptr [ebp + 0x3cc] // 5d | dec eax $sequence_1 = { 4889c1 e8???????? eb07 c745fc01000000 } // n = 4, score = 100 // 4889c1 | mov dword ptr [ebp - 0x38], eax // e8???????? | // eb07 | jmp 0x1e5 // c745fc01000000 | dec eax $sequence_2 = { 488b45e0 0fb74006 0fb7c0 3b45f4 77c7 b800000000 4883c440 } // n = 7, score = 100 // 488b45e0 | dec eax // 0fb74006 | mov ecx, eax // 0fb7c0 | call eax // 3b45f4 | dec eax // 77c7 | mov dword ptr [ebp - 0x18], 0 // b800000000 | mov dword ptr [ebp - 0x34], 0x30 // 4883c440 | mov eax, dword ptr [ebp - 0x34] $sequence_3 = { 4889c1 488b05???????? ffd0 488b45e0 483145f8 48b8ffffffffffff0000 482145f8 } // n = 7, score = 100 // 4889c1 | dec ecx // 488b05???????? | // ffd0 | mov eax, edx // 488b45e0 | dec eax // 483145f8 | lea edx, [0x3cbc] // 48b8ffffffffffff0000 | dec eax // 482145f8 | mov ecx, eax $sequence_4 = { 4889e5 4883ec40 48894d10 c745fc00000000 488b4510 488b4008 } // n = 6, score = 100 // 4889e5 | mov ecx, dword ptr [ebp + 0x10] // 4883ec40 | call eax // 48894d10 | dec eax // c745fc00000000 | cmp eax, -1 // 488b4510 | jne 0x31c // 488b4008 | dec eax $sequence_5 = { 488945f8 488d55d8 488b45f8 41b800000000 4889c1 488b05???????? ffd0 } // n = 7, score = 100 // 488945f8 | mov eax, dword ptr [ebp + 0x10] // 488d55d8 | dec eax // 488b45f8 | mov eax, dword ptr [eax] // 41b800000000 | inc ecx // 4889c1 | mov eax, edx // 488b05???????? | // ffd0 | ja 0x1bd $sequence_6 = { 4889c1 e8???????? 85c0 7507 b800000000 eb22 } // n = 6, score = 100 // 4889c1 | mov eax, dword ptr [ebp - 0x40] // e8???????? | // 85c0 | dec eax // 7507 | add eax, edx // b800000000 | dec eax // eb22 | shl eax, 3 $sequence_7 = { ac 30e0 aa e2fa } // n = 4, score = 100 // ac | jne 0x64a // 30e0 | dec eax // aa | mov eax, dword ptr [ebp + 0x10] // e2fa | dec eax $sequence_8 = { 48898590000000 488b85e0020000 488b4018 48898598000000 488b85e0020000 488b4020 } // n = 6, score = 100 // 48898590000000 | dec eax // 488b85e0020000 | mov edx, dword ptr [ebp - 0x48] // 488b4018 | dec eax // 48898598000000 | add eax, eax // 488b85e0020000 | dec eax // 488b4020 | add eax, edx $sequence_9 = { c70000000000 e8???????? e8???????? 8945fc 90 90 8b45fc } // n = 7, score = 100 // c70000000000 | mov ecx, eax // e8???????? | // e8???????? | // 8945fc | dec eax // 90 | mov eax, dword ptr [ebp - 8] // 90 | dec eax // 8b45fc | lea edx, [eax*8] condition: 7 of them and filesize < 156672 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY