SYMBOLCOMMON_NAMEaka. SYNONYMS
win.nimbo_c2 (Back to overview)

Nimbo-C2

VTCollection    

According to the author, Nimbo-C2 is yet another (simple and lightweight) C2 framework. The agent currently supports Windows x64 and Linux. It's written in Nim, with some usage of .NET (by dynamically loading the CLR to the process).

References
2024-02-06 ⋅ Knownsec ⋅ K&XWS@Knownsec 404
APT-K-47 Organization Launches Espionage Attacks Using a New Trojan Tool
Nimbo-C2 ORPCBackdoor
2024-02-06 ⋅ Knownsec ⋅ Knownsec 404 Team
APT-K-47 Organization Launches Espionage Attacks Using a New Trojan Tool
Nimbo-C2 ORPCBackdoor
2022-10-08 ⋅ Github (itaymigdal) ⋅ Itay Migdal
Nimbo-C2 - A new C2 Framework
Nimbo-C2 Nimbo-C2
Yara Rules
[TLP:WHITE] win_nimbo_c2_auto (20260917 | Detects win.nimbo_c2.)
rule win_nimbo_c2_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.nimbo_c2."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nimbo_c2"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 48837d2800 7429 4889da 488b4d28 4c8b01 4939d0 75ab }
            // n = 7, score = 500
            //   48837d2800           | lea                 eax, [ecx + 0xc0]
            //   7429                 | dec                 eax
            //   4889da               | lea                 eax, [0x4209b]
            //   488b4d28             | dec                 eax
            //   4c8b01               | lea                 eax, [ecx + 0xc0]
            //   4939d0               | dec                 eax
            //   75ab                 | lea                 eax, [0x665ca]

        $sequence_1 = { 7425 e8???????? eb1e e8???????? c6857ffeffff00 48c785f8feffff00000000 e8???????? }
            // n = 7, score = 500
            //   7425                 | dec                 eax
            //   e8????????           |                     
            //   eb1e                 | mov                 eax, dword ptr [ebx + 0x18]
            //   e8????????           |                     
            //   c6857ffeffff00       | mov                 ecx, 0xf
            //   48c785f8feffff00000000     | dec    eax
            //   e8????????           |                     

        $sequence_2 = { 488b12 488910 c3 56 53 4883ec28 4889ce }
            // n = 7, score = 500
            //   488b12               | dec                 ebp
            //   488910               | mov                 eax, ebp
            //   c3                   | dec                 eax
            //   56                   | lea                 edx, [0x281bf]
            //   53                   | dec                 esp
            //   4883ec28             | mov                 ecx, ecx
            //   4889ce               | dec                 esp

        $sequence_3 = { 488b07 488b541820 4a8d0c28 e8???????? 488b0f 31d2 48c744191000000000 }
            // n = 7, score = 500
            //   488b07               | mov                 ecx, esp
            //   488b541820           | mov                 edx, 4
            //   4a8d0c28             | dec                 eax
            //   e8????????           |                     
            //   488b0f               | mov                 dword ptr [ebp - 0x228], eax
            //   31d2                 | dec                 eax
            //   48c744191000000000     | lea    edx, [0x2ca65]

        $sequence_4 = { 488b05???????? ff10 85c0 7544 e8???????? 4c89e9 4189c6 }
            // n = 7, score = 500
            //   488b05????????       |                     
            //   ff10                 | dec                 eax
            //   85c0                 | lea                 edx, [0x2e2f2]
            //   7544                 | dec                 eax
            //   e8????????           |                     
            //   4c89e9               | lea                 ecx, [0x2e32b]
            //   4189c6               | dec                 esp

        $sequence_5 = { 7f1c 488b8df8fbffff e8???????? 4889f2 4989c7 4885c0 7432 }
            // n = 7, score = 500
            //   7f1c                 | lea                 ecx, [0x56d72]
            //   488b8df8fbffff       | movaps              xmm6, xmm0
            //   e8????????           |                     
            //   4889f2               | mov                 byte ptr [eax + 1], 3
            //   4989c7               | movsd               qword ptr [eax + 8], xmm6
            //   4885c0               | movaps              xmmword ptr [esp + 0x20], xmm6
            //   7432                 | mov                 edx, 0x28

        $sequence_6 = { 4889e5 4881ec40010000 48894d10 48895518 4c894520 48c785e8feffff00000000 e8???????? }
            // n = 7, score = 500
            //   4889e5               | dec                 eax
            //   4881ec40010000       | lea                 edx, [0x24a67]
            //   48894d10             | dec                 esp
            //   48895518             | mov                 edx, ecx
            //   4c894520             | dec                 ecx
            //   48c785e8feffff00000000     | lea    ecx, [esp + 0x18]
            //   e8????????           |                     

        $sequence_7 = { e8???????? 488b8510fbffff 4881c440050000 415c 415d 5d c3 }
            // n = 7, score = 500
            //   e8????????           |                     
            //   488b8510fbffff       | js                  0xba1
            //   4881c440050000       | inc                 ecx
            //   415c                 | mov                 eax, 0x87
            //   415d                 | dec                 eax
            //   5d                   | lea                 edx, [0x3219b]
            //   c3                   | dec                 eax

        $sequence_8 = { 415d 415e c3 56 53 4883ec28 4889ce }
            // n = 7, score = 500
            //   415d                 | lea                 edx, [0x1e031]
            //   415e                 | xor                 ecx, ecx
            //   c3                   | dec                 ecx
            //   56                   | mov                 esi, eax
            //   53                   | dec                 eax
            //   4883ec28             | mov                 eax, dword ptr [ebp - 0x150]
            //   4889ce               | dec                 eax

        $sequence_9 = { e8???????? eb54 80fa5d 7447 eb19 4584ed 7445 }
            // n = 7, score = 500
            //   e8????????           |                     
            //   eb54                 | dec                 esp
            //   80fa5d               | mov                 dword ptr [ebp + 0x28], ecx
            //   7447                 | dec                 eax
            //   eb19                 | mov                 dword ptr [ebp + 0x18], edx
            //   4584ed               | dec                 eax
            //   7445                 | mov                 dword ptr [ebp - 0x1a0], 0

    condition:
        7 of them and filesize < 1141760
}
Download all Yara Rules