A spambot that has been observed being used for spreading Ursnif, Zeus Panda, Andromeda or Netflix phishing against Italy and Canada.
rule win_onliner_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.onliner." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.onliner" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 33c6 23c3 33c7 0345fc 0345e0 05aff7448b ba0c000000 } // n = 7, score = 100 // 33c6 | xor eax, esi // 23c3 | and eax, ebx // 33c7 | xor eax, edi // 0345fc | add eax, dword ptr [ebp - 4] // 0345e0 | add eax, dword ptr [ebp - 0x20] // 05aff7448b | add eax, 0x8b44f7af // ba0c000000 | mov edx, 0xc $sequence_1 = { 7435 68???????? ff75c4 68???????? ff75d4 8d854cffffff ba04000000 } // n = 7, score = 100 // 7435 | je 0x37 // 68???????? | // ff75c4 | push dword ptr [ebp - 0x3c] // 68???????? | // ff75d4 | push dword ptr [ebp - 0x2c] // 8d854cffffff | lea eax, [ebp - 0xb4] // ba04000000 | mov edx, 4 $sequence_2 = { 83e804 7420 48 83e80a 7220 eb41 83c0bf } // n = 7, score = 100 // 83e804 | sub eax, 4 // 7420 | je 0x22 // 48 | dec eax // 83e80a | sub eax, 0xa // 7220 | jb 0x22 // eb41 | jmp 0x43 // 83c0bf | add eax, -0x41 $sequence_3 = { 894304 33c0 5a 59 59 648910 68???????? } // n = 7, score = 100 // 894304 | mov dword ptr [ebx + 4], eax // 33c0 | xor eax, eax // 5a | pop edx // 59 | pop ecx // 59 | pop ecx // 648910 | mov dword ptr fs:[eax], edx // 68???????? | $sequence_4 = { 7426 8bc6 e8???????? 8bd8 eb01 4b 85db } // n = 7, score = 100 // 7426 | je 0x28 // 8bc6 | mov eax, esi // e8???????? | // 8bd8 | mov ebx, eax // eb01 | jmp 3 // 4b | dec ebx // 85db | test ebx, ebx $sequence_5 = { 8bc1 c1f805 8bf1 83e61f 8d3c8560f94c00 8b07 } // n = 6, score = 100 // 8bc1 | mov eax, ecx // c1f805 | sar eax, 5 // 8bf1 | mov esi, ecx // 83e61f | and esi, 0x1f // 8d3c8560f94c00 | lea edi, [eax*4 + 0x4cf960] // 8b07 | mov eax, dword ptr [edi] $sequence_6 = { dbac537f364000 def9 c1e805 7434 89c2 83e20f 740c } // n = 7, score = 100 // dbac537f364000 | fld xword ptr [ebx + edx*2 + 0x40367f] // def9 | fdivp st(1) // c1e805 | shr eax, 5 // 7434 | je 0x36 // 89c2 | mov edx, eax // 83e20f | and edx, 0xf // 740c | je 0xe $sequence_7 = { 80ea0a 7405 80ea03 7546 897c2404 8b0424 8bd3 } // n = 7, score = 100 // 80ea0a | sub dl, 0xa // 7405 | je 7 // 80ea03 | sub dl, 3 // 7546 | jne 0x48 // 897c2404 | mov dword ptr [esp + 4], edi // 8b0424 | mov eax, dword ptr [esp] // 8bd3 | mov edx, ebx $sequence_8 = { ba01000000 e8???????? eb60 833d????????01 7557 8b03 } // n = 6, score = 100 // ba01000000 | mov edx, 1 // e8???????? | // eb60 | jmp 0x62 // 833d????????01 | // 7557 | jne 0x59 // 8b03 | mov eax, dword ptr [ebx] $sequence_9 = { 64ff30 648920 8b45f8 e8???????? bb01000000 33ff 8b45fc } // n = 7, score = 100 // 64ff30 | push dword ptr fs:[eax] // 648920 | mov dword ptr fs:[eax], esp // 8b45f8 | mov eax, dword ptr [ebp - 8] // e8???????? | // bb01000000 | mov ebx, 1 // 33ff | xor edi, edi // 8b45fc | mov eax, dword ptr [ebp - 4] condition: 7 of them and filesize < 1736704 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY