SYMBOLCOMMON_NAMEaka. SYNONYMS
win.maktub (Back to overview)

Maktub

VTCollection    

According to PCrisk, Maktub is ransomware distributed via zipped Word documents. Once the file is extracted and opened, Maktub infiltrates the system and encrypts files stored on the victim's computer. Maktub ransomware adds a .NORV, .gyul (or other random) extension to each file encrypted, thus, making it straightforward to determine which files are encrypted.

References
2018-05-29 ⋅ Intezer ⋅ Omri Ben Bassat
Iron Cybercrime Group Under The Scope
Maktub Iron Group
2018-04-10 ⋅ Blaze's Security Blog ⋅ BartBlaze
Maktub ransomware: possibly rebranded as Iron
Maktub
2016-03-24 ⋅ Malwarebytes ⋅ hasherezade
Maktub Locker – Beautiful And Dangerous
Maktub
Yara Rules
[TLP:WHITE] win_maktub_auto (20260917 | Detects win.maktub.)
rule win_maktub_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.maktub."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maktub"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { ffd0 f7d8 1bc0 f7d8 8be5 }
            // n = 5, score = 400
            //   ffd0                 | call                eax
            //   f7d8                 | neg                 eax
            //   1bc0                 | sbb                 eax, eax
            //   f7d8                 | neg                 eax
            //   8be5                 | mov                 esp, ebp

        $sequence_1 = { ff15???????? eb02 33db 8b4df4 }
            // n = 4, score = 300
            //   ff15????????         |                     
            //   eb02                 | jmp                 4
            //   33db                 | xor                 ebx, ebx
            //   8b4df4               | mov                 ecx, dword ptr [ebp - 0xc]

        $sequence_2 = { ff15???????? eb0a 57 6a08 }
            // n = 4, score = 300
            //   ff15????????         |                     
            //   eb0a                 | jmp                 0xc
            //   57                   | push                edi
            //   6a08                 | push                8

        $sequence_3 = { ff15???????? f6c301 0f8414010000 8d46fc }
            // n = 4, score = 300
            //   ff15????????         |                     
            //   f6c301               | test                bl, 1
            //   0f8414010000         | je                  0x11a
            //   8d46fc               | lea                 eax, [esi - 4]

        $sequence_4 = { ff15???????? ff75f8 ff15???????? 5f 5e b801000000 }
            // n = 6, score = 300
            //   ff15????????         |                     
            //   ff75f8               | push                dword ptr [ebp - 8]
            //   ff15????????         |                     
            //   5f                   | pop                 edi
            //   5e                   | pop                 esi
            //   b801000000           | mov                 eax, 1

        $sequence_5 = { ff15???????? eb02 33c0 46 03f0 3b75e0 }
            // n = 6, score = 300
            //   ff15????????         |                     
            //   eb02                 | jmp                 4
            //   33c0                 | xor                 eax, eax
            //   46                   | inc                 esi
            //   03f0                 | add                 esi, eax
            //   3b75e0               | cmp                 esi, dword ptr [ebp - 0x20]

        $sequence_6 = { ff15???????? f6c301 7432 8b75b8 }
            // n = 4, score = 300
            //   ff15????????         |                     
            //   f6c301               | test                bl, 1
            //   7432                 | je                  0x34
            //   8b75b8               | mov                 esi, dword ptr [ebp - 0x48]

        $sequence_7 = { ff7508 ffd7 50 ffd6 53 }
            // n = 5, score = 300
            //   ff7508               | push                dword ptr [ebp + 8]
            //   ffd7                 | call                edi
            //   50                   | push                eax
            //   ffd6                 | call                esi
            //   53                   | push                ebx

        $sequence_8 = { ff30 e8???????? 8bc7 5f 5e 5b }
            // n = 6, score = 200
            //   ff30                 | push                dword ptr [eax]
            //   e8????????           |                     
            //   8bc7                 | mov                 eax, edi
            //   5f                   | pop                 edi
            //   5e                   | pop                 esi
            //   5b                   | pop                 ebx

        $sequence_9 = { 8d55e4 8d4dc4 e8???????? 8bc8 }
            // n = 4, score = 100
            //   8d55e4               | lea                 edx, [ebp - 0x1c]
            //   8d4dc4               | lea                 ecx, [ebp - 0x3c]
            //   e8????????           |                     
            //   8bc8                 | mov                 ecx, eax

        $sequence_10 = { 8d55e4 8d4dec e8???????? 8bce e8???????? 8b4df4 }
            // n = 6, score = 100
            //   8d55e4               | lea                 edx, [ebp - 0x1c]
            //   8d4dec               | lea                 ecx, [ebp - 0x14]
            //   e8????????           |                     
            //   8bce                 | mov                 ecx, esi
            //   e8????????           |                     
            //   8b4df4               | mov                 ecx, dword ptr [ebp - 0xc]

        $sequence_11 = { 8d4383 d1f1 10149d891be6fc ae }
            // n = 4, score = 100
            //   8d4383               | lea                 eax, [ebx - 0x7d]
            //   d1f1                 | sal                 ecx, 1
            //   10149d891be6fc       | adc                 byte ptr [ebx*4 - 0x319e477], dl
            //   ae                   | scasb               al, byte ptr es:[edi]

        $sequence_12 = { 8d55dc 8d8d5cffffff e8???????? 8bd0 }
            // n = 4, score = 100
            //   8d55dc               | lea                 edx, [ebp - 0x24]
            //   8d8d5cffffff         | lea                 ecx, [ebp - 0xa4]
            //   e8????????           |                     
            //   8bd0                 | mov                 edx, eax

        $sequence_13 = { 8d433f e4f2 90 2ab432f35979e3 }
            // n = 4, score = 100
            //   8d433f               | lea                 eax, [ebx + 0x3f]
            //   e4f2                 | in                  al, 0xf2
            //   90                   | nop                 
            //   2ab432f35979e3       | sub                 dh, byte ptr [edx + esi - 0x1c86a60d]

        $sequence_14 = { 8d4310 50 e8???????? 8b7d10 }
            // n = 4, score = 100
            //   8d4310               | lea                 eax, [ebx + 0x10]
            //   50                   | push                eax
            //   e8????????           |                     
            //   8b7d10               | mov                 edi, dword ptr [ebp + 0x10]

        $sequence_15 = { 8d55e8 8bc8 e8???????? 8b4dfc }
            // n = 4, score = 100
            //   8d55e8               | lea                 edx, [ebp - 0x18]
            //   8bc8                 | mov                 ecx, eax
            //   e8????????           |                     
            //   8b4dfc               | mov                 ecx, dword ptr [ebp - 4]

        $sequence_16 = { 8d4320 57 50 e8???????? 83c40c c786f800000001000000 }
            // n = 6, score = 100
            //   8d4320               | lea                 eax, [ebx + 0x20]
            //   57                   | push                edi
            //   50                   | push                eax
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc
            //   c786f800000001000000     | mov    dword ptr [esi + 0xf8], 1

        $sequence_17 = { 8d55e0 8d4d9c e8???????? 8bd0 8d4dcc e8???????? }
            // n = 6, score = 100
            //   8d55e0               | lea                 edx, [ebp - 0x20]
            //   8d4d9c               | lea                 ecx, [ebp - 0x64]
            //   e8????????           |                     
            //   8bd0                 | mov                 edx, eax
            //   8d4dcc               | lea                 ecx, [ebp - 0x34]
            //   e8????????           |                     

        $sequence_18 = { 8d4320 50 ff7360 51 ff74242c }
            // n = 5, score = 100
            //   8d4320               | lea                 eax, [ebx + 0x20]
            //   50                   | push                eax
            //   ff7360               | push                dword ptr [ebx + 0x60]
            //   51                   | push                ecx
            //   ff74242c             | push                dword ptr [esp + 0x2c]

        $sequence_19 = { 8d55e4 8bc8 e8???????? 8b4df4 }
            // n = 4, score = 100
            //   8d55e4               | lea                 edx, [ebp - 0x1c]
            //   8bc8                 | mov                 ecx, eax
            //   e8????????           |                     
            //   8b4df4               | mov                 ecx, dword ptr [ebp - 0xc]

        $sequence_20 = { 8d55ac 8d4d9c e8???????? 8bd0 8d8d74ffffff e8???????? }
            // n = 6, score = 100
            //   8d55ac               | lea                 edx, [ebp - 0x54]
            //   8d4d9c               | lea                 ecx, [ebp - 0x64]
            //   e8????????           |                     
            //   8bd0                 | mov                 edx, eax
            //   8d8d74ffffff         | lea                 ecx, [ebp - 0x8c]
            //   e8????????           |                     

        $sequence_21 = { 8d43eb 83f804 0f8732030000 ff24850cd94300 }
            // n = 4, score = 100
            //   8d43eb               | lea                 eax, [ebx - 0x15]
            //   83f804               | cmp                 eax, 4
            //   0f8732030000         | ja                  0x338
            //   ff24850cd94300       | jmp                 dword ptr [eax*4 + 0x43d90c]

    condition:
        7 of them and filesize < 3063808
}
Download all Yara Rules