There is no description at this point.
rule win_ledgerchecker_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.ledgerchecker." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ledgerchecker" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 488b4220 4883c008 4889442458 498b00 8b00 2bc1 89442450 } // n = 7, score = 100 // 488b4220 | inc eax // 4883c008 | ret // 4889442458 | inc edx // 498b00 | movzx edx, byte ptr [ecx] // 8b00 | inc ebx // 2bc1 | movzx ecx, byte ptr [eax] // 89442450 | cmp ecx, edx $sequence_1 = { e8???????? 488bf0 4885c0 7472 0f57c0 33c0 b901000000 } // n = 7, score = 100 // e8???????? | // 488bf0 | dec eax // 4885c0 | mov esi, dword ptr [esp + 0x50] // 7472 | dec esp // 0f57c0 | mov esi, dword ptr [esp + 0x60] // 33c0 | dec eax // b901000000 | mov ebp, dword ptr [esp + 0x38] $sequence_2 = { eb31 8b542434 8d4101 898790000000 488d0c49 488b8788000000 c704c88bfd0000 } // n = 7, score = 100 // eb31 | mov dword ptr [esp - 0x28], edi // 8b542434 | dec ebp // 8d4101 | mov ecx, dword ptr [esp + 8] // 898790000000 | dec eax // 488d0c49 | mov edx, eax // 488b8788000000 | dec ecx // c704c88bfd0000 | mov ecx, ebp $sequence_3 = { 8b8390000000 4863d2 890491 4883c468 415f 415e 415d } // n = 7, score = 100 // 8b8390000000 | inc ebp // 4863d2 | mov edi, eax // 890491 | dec eax // 4883c468 | mov edi, edx // 415f | dec esp // 415e | mov esi, ecx // 415d | dec eax $sequence_4 = { e9???????? 488bcb ff15???????? 4c8b7c2430 488bd7 498bcd e8???????? } // n = 7, score = 100 // e9???????? | // 488bcb | dec eax // ff15???????? | // 4c8b7c2430 | mov ebx, dword ptr [esp + 0x120] // 488bd7 | dec eax // 498bcd | mov edi, dword ptr [esp + 0xd8] // e8???????? | $sequence_5 = { 85c0 0f852a030000 f6433402 7410 488bcb e8???????? 85c0 } // n = 7, score = 100 // 85c0 | jg 0xc5f // 0f852a030000 | inc esp // f6433402 | mov ecx, edx // 7410 | inc esp // 488bcb | mov dword ptr [esp + 0x20], ebp // e8???????? | // 85c0 | mov edx, 0x48 $sequence_6 = { 807b1100 0f8499000000 836b1401 744d 33ff e9???????? 0f4efd } // n = 7, score = 100 // 807b1100 | mov eax, esi // 0f8499000000 | mov dword ptr [esp + 0x40], eax // 836b1401 | dec ecx // 744d | mov edx, esp // 33ff | dec eax // e9???????? | // 0f4efd | mov eax, dword ptr [ebp - 0x48] $sequence_7 = { c704c888000000 8954c804 44896cc808 896cc80c 48896cc810 e9???????? 488b7f10 } // n = 7, score = 100 // c704c888000000 | movzx ecx, byte ptr [ecx + eax] // 8954c804 | dec eax // 44896cc808 | mov eax, dword ptr [esi + 0x40] // 896cc80c | dec esp // 48896cc810 | mov ecx, ebp // e9???????? | // 488b7f10 | dec eax $sequence_8 = { 891f 48894718 4a8d04ad00000000 4903c5 4c897f08 48c1e004 4883c020 } // n = 7, score = 100 // 891f | movzx ebx, byte ptr [ecx + 0xa] // 48894718 | dec esp // 4a8d04ad00000000 | mov ebp, ecx // 4903c5 | dec ebp // 4c897f08 | mov esi, ecx // 48c1e004 | dec ecx // 4883c020 | mov edi, eax $sequence_9 = { 83fd72 448b4328 8bd6 410f94c1 4889442420 498bce e8???????? } // n = 7, score = 100 // 83fd72 | dec eax // 448b4328 | mov ebx, dword ptr [esp + 0x78] // 8bd6 | dec esp // 410f94c1 | lea ebp, [0xfff670ce] // 4889442420 | dec eax // 498bce | add ebx, 0x30 // e8???????? | condition: 7 of them and filesize < 2333696 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY