Actor(s): MUSTANG PANDA
There is no description at this point.
rule win_mqsttang_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.mqsttang." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mqsttang" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { c7442408c0020000 c7442404???????? c70424???????? e8???????? 8b95ccfcffff 0fb712 8d4ad0 } // n = 7, score = 100 // c7442408c0020000 | mov dword ptr [esp + 8], 0x2c0 // c7442404???????? | // c70424???????? | // e8???????? | // 8b95ccfcffff | mov edx, dword ptr [ebp - 0x334] // 0fb712 | movzx edx, word ptr [edx] // 8d4ad0 | lea ecx, [edx - 0x30] $sequence_1 = { e8???????? 8b530c 8b4210 89c1 83e10e 83f90e 741c } // n = 7, score = 100 // e8???????? | // 8b530c | mov edx, dword ptr [ebx + 0xc] // 8b4210 | mov eax, dword ptr [edx + 0x10] // 89c1 | mov ecx, eax // 83e10e | and ecx, 0xe // 83f90e | cmp ecx, 0xe // 741c | je 0x1e $sequence_2 = { 8d749010 8b10 83fa01 7619 8b4004 8b4c2420 890424 } // n = 7, score = 100 // 8d749010 | lea esi, [eax + edx*4 + 0x10] // 8b10 | mov edx, dword ptr [eax] // 83fa01 | cmp edx, 1 // 7619 | jbe 0x1b // 8b4004 | mov eax, dword ptr [eax + 4] // 8b4c2420 | mov ecx, dword ptr [esp + 0x20] // 890424 | mov dword ptr [esp], eax $sequence_3 = { f0832801 0f8446030000 8b460c 8b10 85d2 0f8419030000 83faff } // n = 7, score = 100 // f0832801 | lock sub dword ptr [eax], 1 // 0f8446030000 | je 0x34c // 8b460c | mov eax, dword ptr [esi + 0xc] // 8b10 | mov edx, dword ptr [eax] // 85d2 | test edx, edx // 0f8419030000 | je 0x31f // 83faff | cmp edx, -1 $sequence_4 = { e8???????? 8bb5a8fcffff 8b4604 8d5801 81fb00010000 899ddcfdffff 0f8f35010000 } // n = 7, score = 100 // e8???????? | // 8bb5a8fcffff | mov esi, dword ptr [ebp - 0x358] // 8b4604 | mov eax, dword ptr [esi + 4] // 8d5801 | lea ebx, [eax + 1] // 81fb00010000 | cmp ebx, 0x100 // 899ddcfdffff | mov dword ptr [ebp - 0x224], ebx // 0f8f35010000 | jg 0x13b $sequence_5 = { 8b4310 89442438 0f87fe000000 8b4208 31c9 25ffffff7f 894c2404 } // n = 7, score = 100 // 8b4310 | mov eax, dword ptr [ebx + 0x10] // 89442438 | mov dword ptr [esp + 0x38], eax // 0f87fe000000 | ja 0x104 // 8b4208 | mov eax, dword ptr [edx + 8] // 31c9 | xor ecx, ecx // 25ffffff7f | and eax, 0x7fffffff // 894c2404 | mov dword ptr [esp + 4], ecx $sequence_6 = { e8???????? 83ec08 8b08 3b8bf0000000 89c2 0f84b8010000 8b442458 } // n = 7, score = 100 // e8???????? | // 83ec08 | sub esp, 8 // 8b08 | mov ecx, dword ptr [eax] // 3b8bf0000000 | cmp ecx, dword ptr [ebx + 0xf0] // 89c2 | mov edx, eax // 0f84b8010000 | je 0x1be // 8b442458 | mov eax, dword ptr [esp + 0x58] $sequence_7 = { 8d0482 39c8 89459c 0f84ae010000 8b45a0 894da4 8d5db0 } // n = 7, score = 100 // 8d0482 | lea eax, [edx + eax*4] // 39c8 | cmp eax, ecx // 89459c | mov dword ptr [ebp - 0x64], eax // 0f84ae010000 | je 0x1b4 // 8b45a0 | mov eax, dword ptr [ebp - 0x60] // 894da4 | mov dword ptr [ebp - 0x5c], ecx // 8d5db0 | lea ebx, [ebp - 0x50] $sequence_8 = { 8d0440 8d04c2 01f2 01f0 39d0 746e 8d7a18 } // n = 7, score = 100 // 8d0440 | lea eax, [eax + eax*2] // 8d04c2 | lea eax, [edx + eax*8] // 01f2 | add edx, esi // 01f0 | add eax, esi // 39d0 | cmp eax, edx // 746e | je 0x70 // 8d7a18 | lea edi, [edx + 0x18] $sequence_9 = { 8d5108 85c0 0f84a1010000 83f8ff 740a f0832a01 0f8447020000 } // n = 7, score = 100 // 8d5108 | lea edx, [ecx + 8] // 85c0 | test eax, eax // 0f84a1010000 | je 0x1a7 // 83f8ff | cmp eax, -1 // 740a | je 0xc // f0832a01 | lock sub dword ptr [edx], 1 // 0f8447020000 | je 0x24d condition: 7 of them and filesize < 12651520 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY