SYMBOLCOMMON_NAMEaka. SYNONYMS
win.nettraveler (Back to overview)

NetTraveler

aka: TravNet

Actor(s): NetTraveler

VTCollection    

There is no description at this point.

References
2020-11-27 ⋅ CYBER GEEKS All Things Infosec ⋅ CyberMasterV
Dissecting APT21 samples using a step-by-step approach
NetTraveler
2017-08-25 ⋅ Kaspersky Labs ⋅ Costin Raiu, Juan Andrés Guerrero-Saade
Walking in your Enemy's Shadow: When Fourth-Party Collection becomes Attribution Hell
NetTraveler RCS WannaCryptor Dancing Salome
2016-07-07 ⋅ Proofpoint ⋅ Axel F
NetTraveler APT Targets Russian, European Interests
NetTraveler APT21
2015-02-06 ⋅ CrowdStrike ⋅ CrowdStrike
CrowdStrike Global Threat Intel Report 2014
BlackPOS CryptoLocker Derusbi Elise Enfal EvilGrab Gameover P2P HttpBrowser MedusaHTTP Mirage Naikon NetTraveler pirpi PlugX Poison Ivy Sakula RAT Sinowal sykipot taidoor
Yara Rules
[TLP:WHITE] win_nettraveler_auto (20260917 | Detects win.nettraveler.)
rule win_nettraveler_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.nettraveler."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nettraveler"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 0fb6443df0 50 68???????? 56 ff15???????? 83c40c }
            // n = 6, score = 100
            //   0fb6443df0           | movzx               eax, byte ptr [ebp + edi - 0x10]
            //   50                   | push                eax
            //   68????????           |                     
            //   56                   | push                esi
            //   ff15????????         |                     
            //   83c40c               | add                 esp, 0xc

        $sequence_1 = { 0f95c0 88440d8c 41 83f938 7cd7 83650800 c745fc1e000000 }
            // n = 7, score = 100
            //   0f95c0               | setne               al
            //   88440d8c             | mov                 byte ptr [ebp + ecx - 0x74], al
            //   41                   | inc                 ecx
            //   83f938               | cmp                 ecx, 0x38
            //   7cd7                 | jl                  0xffffffd9
            //   83650800             | and                 dword ptr [ebp + 8], 0
            //   c745fc1e000000       | mov                 dword ptr [ebp - 4], 0x1e

        $sequence_2 = { 68???????? 50 ff15???????? 8d858cfbffff }
            // n = 4, score = 100
            //   68????????           |                     
            //   50                   | push                eax
            //   ff15????????         |                     
            //   8d858cfbffff         | lea                 eax, [ebp - 0x474]

        $sequence_3 = { 56 e8???????? 83c410 8d8580f1ffff 68???????? 50 ffd7 }
            // n = 7, score = 100
            //   56                   | push                esi
            //   e8????????           |                     
            //   83c410               | add                 esp, 0x10
            //   8d8580f1ffff         | lea                 eax, [ebp - 0xe80]
            //   68????????           |                     
            //   50                   | push                eax
            //   ffd7                 | call                edi

        $sequence_4 = { 57 e8???????? 50 8b45fc 57 8b0406 ff7008 }
            // n = 7, score = 100
            //   57                   | push                edi
            //   e8????????           |                     
            //   50                   | push                eax
            //   8b45fc               | mov                 eax, dword ptr [ebp - 4]
            //   57                   | push                edi
            //   8b0406               | mov                 eax, dword ptr [esi + eax]
            //   ff7008               | push                dword ptr [eax + 8]

        $sequence_5 = { 750b ff45fc 837dfc03 7d34 ebd5 8b45f0 2b4508 }
            // n = 7, score = 100
            //   750b                 | jne                 0xd
            //   ff45fc               | inc                 dword ptr [ebp - 4]
            //   837dfc03             | cmp                 dword ptr [ebp - 4], 3
            //   7d34                 | jge                 0x36
            //   ebd5                 | jmp                 0xffffffd7
            //   8b45f0               | mov                 eax, dword ptr [ebp - 0x10]
            //   2b4508               | sub                 eax, dword ptr [ebp + 8]

        $sequence_6 = { e8???????? ff7514 8d45f4 50 8d45dc 50 ff7508 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   ff7514               | push                dword ptr [ebp + 0x14]
            //   8d45f4               | lea                 eax, [ebp - 0xc]
            //   50                   | push                eax
            //   8d45dc               | lea                 eax, [ebp - 0x24]
            //   50                   | push                eax
            //   ff7508               | push                dword ptr [ebp + 8]

        $sequence_7 = { 8b5d10 8b45fc 2bde 894518 6a01 8d45e4 ff7514 }
            // n = 7, score = 100
            //   8b5d10               | mov                 ebx, dword ptr [ebp + 0x10]
            //   8b45fc               | mov                 eax, dword ptr [ebp - 4]
            //   2bde                 | sub                 ebx, esi
            //   894518               | mov                 dword ptr [ebp + 0x18], eax
            //   6a01                 | push                1
            //   8d45e4               | lea                 eax, [ebp - 0x1c]
            //   ff7514               | push                dword ptr [ebp + 0x14]

        $sequence_8 = { ba???????? 0fb69f4c910010 8d8764910010 807c1dc400 }
            // n = 4, score = 100
            //   ba????????           |                     
            //   0fb69f4c910010       | movzx               ebx, byte ptr [edi + 0x1000914c]
            //   8d8764910010         | lea                 eax, [edi + 0x10009164]
            //   807c1dc400           | cmp                 byte ptr [ebp + ebx - 0x3c], 0

        $sequence_9 = { 0106 33df 035de0 8d8c1935f23abd 8bd9 c1eb16 }
            // n = 6, score = 100
            //   0106                 | add                 dword ptr [esi], eax
            //   33df                 | xor                 ebx, edi
            //   035de0               | add                 ebx, dword ptr [ebp - 0x20]
            //   8d8c1935f23abd       | lea                 ecx, [ecx + ebx - 0x42c50dcb]
            //   8bd9                 | mov                 ebx, ecx
            //   c1eb16               | shr                 ebx, 0x16

    condition:
        7 of them and filesize < 106496
}
[TLP:WHITE] win_nettraveler_w0   (20170521 | Identifiers for NetTraveler DLL)
/*
    This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as    long as you use it under this license.

*/

import "pe"

rule win_nettraveler_w0 {
    meta:
        description = "Identifiers for NetTraveler DLL"
        author = "Katie Kleemola"
        last_updated = "2014-05-20"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nettraveler"
        malpedia_version = "20170521"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    strings:
        //network strings
        $n1 = "?action=updated&hostid="
        $n2 = "travlerbackinfo"
        $n3 = "?action=getcmd&hostid="
        $n4 = "%s?action=gotcmd&hostid="
        $n5 = "%s?hostid=%s&hostname=%s&hostip=%s&filename=%s&filestart=%u&filetext="

        //debugging strings
        $d1 = "\x00Method1 Fail!!!!!\x00"
        $d2 = "\x00Method3 Fail!!!!!\x00"
        $d3 = "\x00method currect:\x00"
        $d4 = /\x00\x00[\w\-]+ is Running!\x00\x00/
        $d5 = "\x00OtherTwo\x00"

    condition:
        any of them
}
[TLP:WHITE] win_nettraveler_w1   (20170521 | Identifiers for netpass variant)
/*
    This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as    long as you use it under this license.

*/

rule win_nettraveler_w1 {
    meta:
        description = "Identifiers for netpass variant"
        author = "Katie Kleemola"
        last_updated = "2014-05-29"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nettraveler"
        malpedia_version = "20170521"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    strings:
        $exif1 = "Device Protect ApplicatioN" wide
        $exif2 = "beep.sys" wide //embedded exe name
        $exif3 = "BEEP Driver" wide //embedded exe description

        $string1 = "\x00NetPass Update\x00"
        $string2 = "\x00%s:DOWNLOAD\x00"
        $string3 = "\x00%s:UPDATE\x00"
        $string4 = "\x00%s:uNINSTALL\x00"

    condition:
        all of ($exif*) or any of ($string*)
}
[TLP:WHITE] win_nettraveler_w2   (20170521 | Export names for dll component)
/*
    This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as    long as you use it under this license.

*/

rule win_nettraveler_w2 {
	meta:
		description = "Export names for dll component"
		author = "Katie Kleemola"
		last_updated = "2014-05-20"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nettraveler"
        malpedia_version = "20170521"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
	
	strings:
		//dll component exports
		$d1 = "?InjectDll@@YAHPAUHWND__@@K@Z"
		$d2 = "?UnmapDll@@YAHXZ"
		$d3 = "?g_bSubclassed@@3HA"
		
	condition:
		any of them
}
Download all Yara Rules