SYMBOLCOMMON_NAMEaka. SYNONYMS
win.moriagent (Back to overview)

MoriAgent

Actor(s): MuddyWater

VTCollection    

There is no description at this point.

References
2022-02-25 ⋅ infoRisk TODAY ⋅ Prajeet Nair
MuddyWater Targets Critical Infrastructure in Asia, Europe
POWERSTATS PowGoop STARWHALE GRAMDOOR MoriAgent
2022-02-24 ⋅ CISA, CNMF, FBI, NCSC UK
Alert (AA22-055A) Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks
POWERSTATS PowGoop MoriAgent
2022-02-24 ⋅ CISA, CNMF, FBI, NCSC UK, NSA
Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks
POWERSTATS PowGoop GRAMDOOR MoriAgent
2022-01-12 ⋅ U.S. Cyber Command ⋅ U.S. Cyber Command
Iranian intel cyber suite of malware uses open source tools
PowGoop MoriAgent
2020-11-03 ⋅ Kaspersky Labs ⋅ GReAT
APT trends report Q3 2020
WellMail EVILNUM Janicab Poet RAT AsyncRAT Ave Maria Cobalt Strike Crimson RAT CROSSWALK Dtrack LODEINFO MoriAgent Okrum PlugX POISONPLUG Rover ShadowPad SoreFang Winnti
2020-06-17 ⋅ Twitter (@Timele9527) ⋅ Timele12138
Tweet on MoriAgent uesd by MuddyWater (incl YARA rule)
MoriAgent
2020-05-07 ⋅ paloalto LIVEcommunity ⋅ Mohammed Yasin
How to stop MortiAgent Malware using the snort rule?
MoriAgent
Yara Rules
[TLP:WHITE] win_moriagent_auto (20260917 | Detects win.moriagent.)
rule win_moriagent_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.moriagent."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.moriagent"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { c746140f000000 c60600 8d4734 c7401000000000 8945c4 c740140f000000 c60000 }
            // n = 7, score = 100
            //   c746140f000000       | mov                 dword ptr [esi + 0x14], 0xf
            //   c60600               | mov                 byte ptr [esi], 0
            //   8d4734               | lea                 eax, [edi + 0x34]
            //   c7401000000000       | mov                 dword ptr [eax + 0x10], 0
            //   8945c4               | mov                 dword ptr [ebp - 0x3c], eax
            //   c740140f000000       | mov                 dword ptr [eax + 0x14], 0xf
            //   c60000               | mov                 byte ptr [eax], 0

        $sequence_1 = { c685b4efffff00 e8???????? 8d8dccefffff e8???????? 8d8dd4efffff e8???????? 8d4d0c }
            // n = 7, score = 100
            //   c685b4efffff00       | mov                 byte ptr [ebp - 0x104c], 0
            //   e8????????           |                     
            //   8d8dccefffff         | lea                 ecx, [ebp - 0x1034]
            //   e8????????           |                     
            //   8d8dd4efffff         | lea                 ecx, [ebp - 0x102c]
            //   e8????????           |                     
            //   8d4d0c               | lea                 ecx, [ebp + 0xc]

        $sequence_2 = { 7231 8b95d0eeffff 8d4801 8bc2 81f900100000 7214 }
            // n = 6, score = 100
            //   7231                 | jb                  0x33
            //   8b95d0eeffff         | mov                 edx, dword ptr [ebp - 0x1130]
            //   8d4801               | lea                 ecx, [eax + 1]
            //   8bc2                 | mov                 eax, edx
            //   81f900100000         | cmp                 ecx, 0x1000
            //   7214                 | jb                  0x16

        $sequence_3 = { 660f28aa603a4200 660f54e5 660f58fe 660f58fc 660f59c8 f20f59d8 660f58ca }
            // n = 7, score = 100
            //   660f28aa603a4200     | movapd              xmm5, xmmword ptr [edx + 0x423a60]
            //   660f54e5             | andpd               xmm4, xmm5
            //   660f58fe             | addpd               xmm7, xmm6
            //   660f58fc             | addpd               xmm7, xmm4
            //   660f59c8             | mulpd               xmm1, xmm0
            //   f20f59d8             | mulsd               xmm3, xmm0
            //   660f58ca             | addpd               xmm1, xmm2

        $sequence_4 = { 7408 41 83f940 7cf2 33c9 }
            // n = 5, score = 100
            //   7408                 | je                  0xa
            //   41                   | inc                 ecx
            //   83f940               | cmp                 ecx, 0x40
            //   7cf2                 | jl                  0xfffffff4
            //   33c9                 | xor                 ecx, ecx

        $sequence_5 = { 8b75d4 2bf7 90 0fbe07 50 e8???????? }
            // n = 6, score = 100
            //   8b75d4               | mov                 esi, dword ptr [ebp - 0x2c]
            //   2bf7                 | sub                 esi, edi
            //   90                   | nop                 
            //   0fbe07               | movsx               eax, byte ptr [edi]
            //   50                   | push                eax
            //   e8????????           |                     

        $sequence_6 = { 8bc8 3bb5f0eeffff 0f849a0e0000 8b85d8eeffff 833822 0f84810e0000 }
            // n = 6, score = 100
            //   8bc8                 | mov                 ecx, eax
            //   3bb5f0eeffff         | cmp                 esi, dword ptr [ebp - 0x1110]
            //   0f849a0e0000         | je                  0xea0
            //   8b85d8eeffff         | mov                 eax, dword ptr [ebp - 0x1128]
            //   833822               | cmp                 dword ptr [eax], 0x22
            //   0f84810e0000         | je                  0xe87

        $sequence_7 = { 83a5b8eeffffdf 8d8d84efffff e9???????? c3 8d8d54efffff e9???????? 8d8d84efffff }
            // n = 7, score = 100
            //   83a5b8eeffffdf       | and                 dword ptr [ebp - 0x1148], 0xffffffdf
            //   8d8d84efffff         | lea                 ecx, [ebp - 0x107c]
            //   e9????????           |                     
            //   c3                   | ret                 
            //   8d8d54efffff         | lea                 ecx, [ebp - 0x10ac]
            //   e9????????           |                     
            //   8d8d84efffff         | lea                 ecx, [ebp - 0x107c]

        $sequence_8 = { 6a00 50 e8???????? 83c40c c7442408bc030000 8d442408 8974240c }
            // n = 7, score = 100
            //   6a00                 | push                0
            //   50                   | push                eax
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc
            //   c7442408bc030000     | mov                 dword ptr [esp + 8], 0x3bc
            //   8d442408             | lea                 eax, [esp + 8]
            //   8974240c             | mov                 dword ptr [esp + 0xc], esi

        $sequence_9 = { 3c02 8bc6 7518 c60601 5e 8b8c2498010000 33cc }
            // n = 7, score = 100
            //   3c02                 | cmp                 al, 2
            //   8bc6                 | mov                 eax, esi
            //   7518                 | jne                 0x1a
            //   c60601               | mov                 byte ptr [esi], 1
            //   5e                   | pop                 esi
            //   8b8c2498010000       | mov                 ecx, dword ptr [esp + 0x198]
            //   33cc                 | xor                 ecx, esp

    condition:
        7 of them and filesize < 720896
}
Download all Yara Rules