SYMBOLCOMMON_NAMEaka. SYNONYMS
win.nymaim2 (Back to overview)

Nymaim2

VTCollection    

According to bin.re, in April 2018 a new version of Nymaim appeared, that has dropped previous obfuscation, and uses a new wordlist based DGA (Domain Generation Algorithm).

References
2022-09-15 ⋅ Sekoia ⋅ Threat & Detection Research Team
PrivateLoader: the loader of the prevalent ruzki PPI service
Agent Tesla Coinminer DanaBot DCRat Eternity Stealer Glupteba Mars Stealer NetSupportManager RAT Nymaim Nymaim2 Phoenix Keylogger PrivateLoader Raccoon RedLine Stealer SmokeLoader Socelars STOP Vidar YTStealer
2018-04-29 ⋅ Johannes Bader
The new Domain Generation Algorithm of Nymaim
Nymaim2
Yara Rules
[TLP:WHITE] win_nymaim2_auto (20260917 | Detects win.nymaim2.)
rule win_nymaim2_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.nymaim2."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.nymaim2"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { c20800 b8???????? e8???????? 51 53 8b1d???????? 56 }
            // n = 7, score = 200
            //   c20800               | ret                 8
            //   b8????????           |                     
            //   e8????????           |                     
            //   51                   | push                ecx
            //   53                   | push                ebx
            //   8b1d????????         |                     
            //   56                   | push                esi

        $sequence_1 = { e8???????? e8???????? 59 3ac3 59 7525 68???????? }
            // n = 7, score = 200
            //   e8????????           |                     
            //   e8????????           |                     
            //   59                   | pop                 ecx
            //   3ac3                 | cmp                 al, bl
            //   59                   | pop                 ecx
            //   7525                 | jne                 0x27
            //   68????????           |                     

        $sequence_2 = { 8d4df0 5e 6a0a 6a10 8975fc e8???????? }
            // n = 6, score = 200
            //   8d4df0               | lea                 ecx, [ebp - 0x10]
            //   5e                   | pop                 esi
            //   6a0a                 | push                0xa
            //   6a10                 | push                0x10
            //   8975fc               | mov                 dword ptr [ebp - 4], esi
            //   e8????????           |                     

        $sequence_3 = { 894658 894654 894650 894e48 8d4e5c c645fc04 }
            // n = 6, score = 200
            //   894658               | mov                 dword ptr [esi + 0x58], eax
            //   894654               | mov                 dword ptr [esi + 0x54], eax
            //   894650               | mov                 dword ptr [esi + 0x50], eax
            //   894e48               | mov                 dword ptr [esi + 0x48], ecx
            //   8d4e5c               | lea                 ecx, [esi + 0x5c]
            //   c645fc04             | mov                 byte ptr [ebp - 4], 4

        $sequence_4 = { c745fc07000000 e8???????? 8bf8 8a45f3 53 8d4dd4 8845d4 }
            // n = 7, score = 200
            //   c745fc07000000       | mov                 dword ptr [ebp - 4], 7
            //   e8????????           |                     
            //   8bf8                 | mov                 edi, eax
            //   8a45f3               | mov                 al, byte ptr [ebp - 0xd]
            //   53                   | push                ebx
            //   8d4dd4               | lea                 ecx, [ebp - 0x2c]
            //   8845d4               | mov                 byte ptr [ebp - 0x2c], al

        $sequence_5 = { 53 8b35???????? 53 c645fc02 ff750c 57 53 }
            // n = 7, score = 200
            //   53                   | push                ebx
            //   8b35????????         |                     
            //   53                   | push                ebx
            //   c645fc02             | mov                 byte ptr [ebp - 4], 2
            //   ff750c               | push                dword ptr [ebp + 0xc]
            //   57                   | push                edi
            //   53                   | push                ebx

        $sequence_6 = { 25ff000000 0fb6c0 c1e208 0bd0 8911 c7460432000000 8b4e20 }
            // n = 7, score = 200
            //   25ff000000           | and                 eax, 0xff
            //   0fb6c0               | movzx               eax, al
            //   c1e208               | shl                 edx, 8
            //   0bd0                 | or                  edx, eax
            //   8911                 | mov                 dword ptr [ecx], edx
            //   c7460432000000       | mov                 dword ptr [esi + 4], 0x32
            //   8b4e20               | mov                 ecx, dword ptr [esi + 0x20]

        $sequence_7 = { 8d45f0 8bcc 8965d0 50 e8???????? 8d45b0 }
            // n = 6, score = 200
            //   8d45f0               | lea                 eax, [ebp - 0x10]
            //   8bcc                 | mov                 ecx, esp
            //   8965d0               | mov                 dword ptr [ebp - 0x30], esp
            //   50                   | push                eax
            //   e8????????           |                     
            //   8d45b0               | lea                 eax, [ebp - 0x50]

        $sequence_8 = { 83c002 8945b0 c746041e000000 8b4e20 83f903 7d3b 8b06 }
            // n = 7, score = 200
            //   83c002               | add                 eax, 2
            //   8945b0               | mov                 dword ptr [ebp - 0x50], eax
            //   c746041e000000       | mov                 dword ptr [esi + 4], 0x1e
            //   8b4e20               | mov                 ecx, dword ptr [esi + 0x20]
            //   83f903               | cmp                 ecx, 3
            //   7d3b                 | jge                 0x3d
            //   8b06                 | mov                 eax, dword ptr [esi]

        $sequence_9 = { 8d4dec c645fc06 e8???????? 8d4de8 c645fc04 e8???????? 8d45c4 }
            // n = 7, score = 200
            //   8d4dec               | lea                 ecx, [ebp - 0x14]
            //   c645fc06             | mov                 byte ptr [ebp - 4], 6
            //   e8????????           |                     
            //   8d4de8               | lea                 ecx, [ebp - 0x18]
            //   c645fc04             | mov                 byte ptr [ebp - 4], 4
            //   e8????????           |                     
            //   8d45c4               | lea                 eax, [ebp - 0x3c]

    condition:
        7 of them and filesize < 753664
}
Download all Yara Rules