Actor(s): WildNeutron
There is no description at this point.
rule win_jripbot_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.jripbot." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jripbot" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 66837dec01 7e02 8bc1 0fbf4df4 53 51 0fbf4df2 } // n = 7, score = 100 // 66837dec01 | cmp word ptr [ebp - 0x14], 1 // 7e02 | jle 4 // 8bc1 | mov eax, ecx // 0fbf4df4 | movsx ecx, word ptr [ebp - 0xc] // 53 | push ebx // 51 | push ecx // 0fbf4df2 | movsx ecx, word ptr [ebp - 0xe] $sequence_1 = { 8945fc 85c0 757c 8b5708 8b4e08 33ff 85db } // n = 7, score = 100 // 8945fc | mov dword ptr [ebp - 4], eax // 85c0 | test eax, eax // 757c | jne 0x7e // 8b5708 | mov edx, dword ptr [edi + 8] // 8b4e08 | mov ecx, dword ptr [esi + 8] // 33ff | xor edi, edi // 85db | test ebx, ebx $sequence_2 = { 740e 830eff 53 8bde 8bc6 e8???????? 59 } // n = 7, score = 100 // 740e | je 0x10 // 830eff | or dword ptr [esi], 0xffffffff // 53 | push ebx // 8bde | mov ebx, esi // 8bc6 | mov eax, esi // e8???????? | // 59 | pop ecx $sequence_3 = { e8???????? 83c40c 017e24 33c0 e9???????? 8b5d10 } // n = 6, score = 100 // e8???????? | // 83c40c | add esp, 0xc // 017e24 | add dword ptr [esi + 0x24], edi // 33c0 | xor eax, eax // e9???????? | // 8b5d10 | mov ebx, dword ptr [ebp + 0x10] $sequence_4 = { 8d442428 50 ff15???????? 85c0 7431 ff74241c 8b5c241c } // n = 7, score = 100 // 8d442428 | lea eax, [esp + 0x28] // 50 | push eax // ff15???????? | // 85c0 | test eax, eax // 7431 | je 0x33 // ff74241c | push dword ptr [esp + 0x1c] // 8b5c241c | mov ebx, dword ptr [esp + 0x1c] $sequence_5 = { 83f801 7e72 8b5f10 33f6 3bde 7429 3935???????? } // n = 7, score = 100 // 83f801 | cmp eax, 1 // 7e72 | jle 0x74 // 8b5f10 | mov ebx, dword ptr [edi + 0x10] // 33f6 | xor esi, esi // 3bde | cmp ebx, esi // 7429 | je 0x2b // 3935???????? | $sequence_6 = { ff7508 8945e4 ffd7 33f6 895de0 395d10 725e } // n = 7, score = 100 // ff7508 | push dword ptr [ebp + 8] // 8945e4 | mov dword ptr [ebp - 0x1c], eax // ffd7 | call edi // 33f6 | xor esi, esi // 895de0 | mov dword ptr [ebp - 0x20], ebx // 395d10 | cmp dword ptr [ebp + 0x10], ebx // 725e | jb 0x60 $sequence_7 = { 8b8eb8000000 8a10 885105 0138 33c0 5f } // n = 6, score = 100 // 8b8eb8000000 | mov ecx, dword ptr [esi + 0xb8] // 8a10 | mov dl, byte ptr [eax] // 885105 | mov byte ptr [ecx + 5], dl // 0138 | add dword ptr [eax], edi // 33c0 | xor eax, eax // 5f | pop edi $sequence_8 = { 59 ff742410 8d8424f4000000 53 6a01 50 ffd7 } // n = 7, score = 100 // 59 | pop ecx // ff742410 | push dword ptr [esp + 0x10] // 8d8424f4000000 | lea eax, [esp + 0xf4] // 53 | push ebx // 6a01 | push 1 // 50 | push eax // ffd7 | call edi $sequence_9 = { ffd6 33f6 39742438 7418 ff742438 ff15???????? ff742438 } // n = 7, score = 100 // ffd6 | call esi // 33f6 | xor esi, esi // 39742438 | cmp dword ptr [esp + 0x38], esi // 7418 | je 0x1a // ff742438 | push dword ptr [esp + 0x38] // ff15???????? | // ff742438 | push dword ptr [esp + 0x38] condition: 7 of them and filesize < 507904 }
rule win_jripbot_w0 { meta: author = "Florian Roth" reference = "https://securelist.com/blog/research/71275/wild-neutron-economic-espionage-threat-actor-returns-with-new-tricks/" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.jripbot" malpedia_version = "20180301" malpedia_license = "CC BY-NC-SA 4.0" malpedia_sharing = "TLP:WHITE" strings: $s0 = "LiveUpdater.exe" fullword wide /* PEStudio Blacklist: strings */ /* score: '25.00' */ $s1 = "id-at-postalAddress" fullword ascii /* PEStudio Blacklist: strings */ /* score: '18.00' */ $s2 = "%d -> %d (default)" fullword wide /* PEStudio Blacklist: strings */ /* score: '17.00' */ $s3 = "%s%s%s=%d,%s=%d,%s=%d," fullword wide /* score: '15.00' */ $s8 = "id-ce-keyUsage" fullword ascii /* score: '12.00' */ $s9 = "Key Usage" fullword ascii /* score: '12.00' */ $s32 = "UPDATE_ID" fullword wide /* PEStudio Blacklist: strings */ /* score: '9.00' */ $s37 = "id-at-commonName" fullword ascii /* score: '8.00' */ $s38 = "2008R2" fullword wide /* PEStudio Blacklist: os */ /* score: '8.00' */ $s39 = "RSA-alt" fullword ascii /* PEStudio Blacklist: strings */ /* score: '8.00' */ $s40 = "%02d.%04d.%s" fullword wide /* score: '7.02' */ condition: all of them }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY