Ransomware, potential rebranding of win.sfile.
rule win_mindware_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.mindware." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mindware" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 8bcb c1e910 0fb6c9 c1e608 0fb689f0d84400 33f1 } // n = 6, score = 100 // 8bcb | mov ecx, ebx // c1e910 | shr ecx, 0x10 // 0fb6c9 | movzx ecx, cl // c1e608 | shl esi, 8 // 0fb689f0d84400 | movzx ecx, byte ptr [ecx + 0x44d8f0] // 33f1 | xor esi, ecx $sequence_1 = { 8b4df8 c1e908 0fb6c9 8b1495c0c04400 8b75f4 33148dc0bc4400 8bce } // n = 7, score = 100 // 8b4df8 | mov ecx, dword ptr [ebp - 8] // c1e908 | shr ecx, 8 // 0fb6c9 | movzx ecx, cl // 8b1495c0c04400 | mov edx, dword ptr [edx*4 + 0x44c0c0] // 8b75f4 | mov esi, dword ptr [ebp - 0xc] // 33148dc0bc4400 | xor edx, dword ptr [ecx*4 + 0x44bcc0] // 8bce | mov ecx, esi $sequence_2 = { 3945f8 741f 8b34bdd4214400 47 85f6 7fb9 5f } // n = 7, score = 100 // 3945f8 | cmp dword ptr [ebp - 8], eax // 741f | je 0x21 // 8b34bdd4214400 | mov esi, dword ptr [edi*4 + 0x4421d4] // 47 | inc edi // 85f6 | test esi, esi // 7fb9 | jg 0xffffffbb // 5f | pop edi $sequence_3 = { 0bd9 8945f4 b130 8b04d520414400 8b14d524414400 e8???????? 8b4df0 } // n = 7, score = 100 // 0bd9 | or ebx, ecx // 8945f4 | mov dword ptr [ebp - 0xc], eax // b130 | mov cl, 0x30 // 8b04d520414400 | mov eax, dword ptr [edx*8 + 0x444120] // 8b14d524414400 | mov edx, dword ptr [edx*8 + 0x444124] // e8???????? | // 8b4df0 | mov ecx, dword ptr [ebp - 0x10] $sequence_4 = { 2b55e4 8b45d4 1bc1 8955d0 8945d4 8b4de4 33d2 } // n = 7, score = 100 // 2b55e4 | sub edx, dword ptr [ebp - 0x1c] // 8b45d4 | mov eax, dword ptr [ebp - 0x2c] // 1bc1 | sbb eax, ecx // 8955d0 | mov dword ptr [ebp - 0x30], edx // 8945d4 | mov dword ptr [ebp - 0x2c], eax // 8b4de4 | mov ecx, dword ptr [ebp - 0x1c] // 33d2 | xor edx, edx $sequence_5 = { c78588f0ffff2cdf4300 c7858cf0ffff3cdf4300 c78590f0ffff44df4300 c78594f0ffff4cdf4300 } // n = 4, score = 100 // c78588f0ffff2cdf4300 | mov dword ptr [ebp - 0xf78], 0x43df2c // c7858cf0ffff3cdf4300 | mov dword ptr [ebp - 0xf74], 0x43df3c // c78590f0ffff44df4300 | mov dword ptr [ebp - 0xf70], 0x43df44 // c78594f0ffff4cdf4300 | mov dword ptr [ebp - 0xf6c], 0x43df4c $sequence_6 = { 83e1f0 83f910 7309 c745e810000000 eb0f 8b55f8 8b4204 } // n = 7, score = 100 // 83e1f0 | and ecx, 0xfffffff0 // 83f910 | cmp ecx, 0x10 // 7309 | jae 0xb // c745e810000000 | mov dword ptr [ebp - 0x18], 0x10 // eb0f | jmp 0x11 // 8b55f8 | mov edx, dword ptr [ebp - 8] // 8b4204 | mov eax, dword ptr [edx + 4] $sequence_7 = { c785ccf1ffff40e24300 c785d0f1ffff50e24300 c785d4f1ffff60e24300 c785d8f1ffff68e24300 c785dcf1ffff70e24300 c785e0f1ffff7ce24300 c785e4f1ffff8ce24300 } // n = 7, score = 100 // c785ccf1ffff40e24300 | mov dword ptr [ebp - 0xe34], 0x43e240 // c785d0f1ffff50e24300 | mov dword ptr [ebp - 0xe30], 0x43e250 // c785d4f1ffff60e24300 | mov dword ptr [ebp - 0xe2c], 0x43e260 // c785d8f1ffff68e24300 | mov dword ptr [ebp - 0xe28], 0x43e268 // c785dcf1ffff70e24300 | mov dword ptr [ebp - 0xe24], 0x43e270 // c785e0f1ffff7ce24300 | mov dword ptr [ebp - 0xe20], 0x43e27c // c785e4f1ffff8ce24300 | mov dword ptr [ebp - 0xe1c], 0x43e28c $sequence_8 = { 884103 0fb64104 d1e8 0fb68060364400 884104 } // n = 5, score = 100 // 884103 | mov byte ptr [ecx + 3], al // 0fb64104 | movzx eax, byte ptr [ecx + 4] // d1e8 | shr eax, 1 // 0fb68060364400 | movzx eax, byte ptr [eax + 0x443660] // 884104 | mov byte ptr [ecx + 4], al $sequence_9 = { c78550f3ffff38e64300 c78554f3ffff40e64300 c78558f3ffff48e64300 c7855cf3ffff50e64300 c78560f3ffff58e64300 c78564f3ffff60e64300 } // n = 6, score = 100 // c78550f3ffff38e64300 | mov dword ptr [ebp - 0xcb0], 0x43e638 // c78554f3ffff40e64300 | mov dword ptr [ebp - 0xcac], 0x43e640 // c78558f3ffff48e64300 | mov dword ptr [ebp - 0xca8], 0x43e648 // c7855cf3ffff50e64300 | mov dword ptr [ebp - 0xca4], 0x43e650 // c78560f3ffff58e64300 | mov dword ptr [ebp - 0xca0], 0x43e658 // c78564f3ffff60e64300 | mov dword ptr [ebp - 0xc9c], 0x43e660 condition: 7 of them and filesize < 661504 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY