Actor(s): Lazarus Group
There is no description at this point.
rule win_op_blockbuster_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.op_blockbuster." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.op_blockbuster" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 6a00 e8???????? 85c0 7407 83f802 } // n = 5, score = 800 // 6a00 | cmp cl, 0x20 // e8???????? | // 85c0 | jne 7 // 7407 | add eax, 0x21 // 83f802 | jmp 0xc $sequence_1 = { f3ab 66ab aa 5f 85f6 } // n = 5, score = 800 // f3ab | add al, 9 // 66ab | jmp 0xa // aa | jl 0xa // 5f | cmp al, 0x70 // 85f6 | jg 6 $sequence_2 = { 8a08 80f920 7505 83c021 } // n = 4, score = 800 // 8a08 | add al, 9 // 80f920 | cmp al, 0x69 // 7505 | jl 0xc // 83c021 | cmp al, 0x70 $sequence_3 = { e8???????? 6800400000 6a00 ff15???????? } // n = 4, score = 800 // e8???????? | // 6800400000 | je 0xb // 6a00 | push ecx // ff15???????? | $sequence_4 = { ff15???????? 6808400000 6a40 ff15???????? } // n = 4, score = 800 // ff15???????? | // 6808400000 | mov ecx, dword ptr [ecx + 0x7c] // 6a40 | test ecx, ecx // ff15???????? | $sequence_5 = { c701???????? 8b497c 85c9 7407 } // n = 4, score = 800 // c701???????? | // 8b497c | cmp al, 0x72 // 85c9 | cmp al, 0x70 // 7407 | jg 8 $sequence_6 = { 57 683c400000 6a40 ff15???????? } // n = 4, score = 800 // 57 | push esi // 683c400000 | test eax, eax // 6a40 | push 0 // ff15???????? | $sequence_7 = { 68???????? 56 ff15???????? 68???????? 56 a3???????? e8???????? } // n = 7, score = 700 // 68???????? | // 56 | lea eax, [ebp - 4] // ff15???????? | // 68???????? | // 56 | push 4 // a3???????? | // e8???????? | $sequence_8 = { 56 50 8d45fc 6a04 50 57 ff15???????? } // n = 7, score = 700 // 56 | addpd xmm7, xmm6 // 50 | addpd xmm7, xmm4 // 8d45fc | mulpd xmm1, xmm0 // 6a04 | mulsd xmm3, xmm0 // 50 | addpd xmm1, xmm2 // 57 | imul ecx, ecx, 0x30 // ff15???????? | $sequence_9 = { ff15???????? 85c0 7412 68???????? 50 e8???????? } // n = 6, score = 700 // ff15???????? | // 85c0 | cmp eax, 7 // 7412 | ja 0x94 // 68???????? | // 50 | jmp dword ptr [eax*4 + 0x40678b] // e8???????? | $sequence_10 = { 3c69 7c08 3c70 7f04 } // n = 4, score = 500 // 3c69 | cmp al, 0x69 // 7c08 | jl 0xa // 3c70 | cmp al, 0x70 // 7f04 | jg 6 $sequence_11 = { 7f04 0409 eb06 3c72 } // n = 4, score = 500 // 7f04 | jg 6 // 0409 | add al, 9 // eb06 | jmp 8 // 3c72 | cmp al, 0x72 $sequence_12 = { 8bf0 ff15???????? 85f6 7404 85c0 } // n = 5, score = 300 // 8bf0 | pop edi // ff15???????? | // 85f6 | pop esi // 7404 | ret // 85c0 | xor eax, eax $sequence_13 = { 48895c2408 57 4883ec50 488bc2 4533c9 } // n = 5, score = 300 // 48895c2408 | dec ebp // 57 | mov ecx, esp // 4883ec50 | inc ecx // 488bc2 | mov eax, 4 // 4533c9 | dec eax $sequence_14 = { 5e c3 68???????? ff15???????? 85c0 7412 } // n = 6, score = 300 // 5e | push eax // c3 | pop ecx // 68???????? | // ff15???????? | // 85c0 | push eax // 7412 | pop ecx $sequence_15 = { 6a00 ff15???????? 8bf8 85ff 7504 5f } // n = 6, score = 300 // 6a00 | push 0 // ff15???????? | // 8bf8 | mov eax, esi // 85ff | pop edi // 7504 | pop esi // 5f | ret $sequence_16 = { 488d542444 4d8bcc 41b804000000 488bcd c744242001000000 } // n = 5, score = 300 // 488d542444 | inc ebp // 4d8bcc | xor ecx, ecx // 41b804000000 | mov edx, 0x12347a // 488bcd | dec eax // c744242001000000 | lea edx, [esp + 0x44] $sequence_17 = { 57 e8???????? 56 e8???????? 83c414 b801000000 } // n = 6, score = 300 // 57 | je 6 // e8???????? | // 56 | test eax, eax // e8???????? | // 83c414 | push 0 // b801000000 | mov edi, eax $sequence_18 = { 8bc6 5f 5e c3 33c0 6a00 39442408 } // n = 7, score = 300 // 8bc6 | stosw word ptr es:[edi], ax // 5f | stosb byte ptr es:[edi], al // 5e | pop edi // c3 | test esi, esi // 33c0 | pop esi // 6a00 | push esi // 39442408 | push esi $sequence_19 = { 48898424d0070000 488bfa 4533c9 ba7a341200 } // n = 4, score = 300 // 48898424d0070000 | dec eax // 488bfa | mov dword ptr [esp + 0x7d0], eax // 4533c9 | dec eax // ba7a341200 | mov edi, edx $sequence_20 = { 488d4d70 e8???????? 8d43fd e9???????? 4533c9 } // n = 5, score = 300 // 488d4d70 | mov ecx, ebp // e8???????? | // 8d43fd | mov dword ptr [esp + 0x20], 1 // e9???????? | // 4533c9 | dec eax $sequence_21 = { ebf8 53 33db 391d???????? 56 57 7542 } // n = 7, score = 300 // ebf8 | push 0x403c // 53 | push 0x40 // 33db | push 0 // 391d???????? | // 56 | test eax, eax // 57 | je 9 // 7542 | cmp eax, 2 $sequence_22 = { c3 56 53 6a01 57 } // n = 5, score = 300 // c3 | jmp 0xfffffffa // 56 | push ebx // 53 | xor ebx, ebx // 6a01 | push esi // 57 | mov eax, esi $sequence_23 = { 83c714 890431 8b4580 89443104 488b442438 44896c3110 } // n = 6, score = 300 // 83c714 | dec eax // 890431 | mov eax, edx // 8b4580 | inc ebp // 89443104 | xor ecx, ecx // 488b442438 | dec eax // 44896c3110 | lea ecx, [ebp + 0x70] $sequence_24 = { ff15???????? 8b4c2468 488d95e0030000 e8???????? 488d8de0030000 448be8 } // n = 6, score = 300 // ff15???????? | // 8b4c2468 | mov dword ptr [esp + 8], ebx // 488d95e0030000 | push edi // e8???????? | // 488d8de0030000 | dec eax // 448be8 | sub esp, 0x50 $sequence_25 = { 68???????? 56 e8???????? 56 e8???????? 83c438 } // n = 6, score = 300 // 68???????? | // 56 | add esp, 0x14 // e8???????? | // 56 | mov eax, 1 // e8???????? | // 83c438 | ret $sequence_26 = { 660f28aaf0534400 660f54e5 660f58fe 660f58fc 660f59c8 f20f59d8 660f58ca } // n = 7, score = 200 // 660f28aaf0534400 | push 0 // 660f54e5 | mov edi, eax // 660f58fe | test edi, edi // 660f58fc | jne 0xa // 660f59c8 | pop edi // f20f59d8 | push 0 // 660f58ca | mov edi, eax $sequence_27 = { 6bc930 53 8b5d10 8b0485d8974400 56 8b7508 57 } // n = 7, score = 200 // 6bc930 | test edi, edi // 53 | jne 8 // 8b5d10 | pop edi // 8b0485d8974400 | pop esi // 56 | push ebx // 8b7508 | push 1 // 57 | push edi $sequence_28 = { 83f807 0f8786000000 ff24858b674000 68???????? eb13 } // n = 5, score = 200 // 83f807 | test esi, esi // 0f8786000000 | je 8 // ff24858b674000 | test eax, eax // 68???????? | // eb13 | push esi $sequence_29 = { 8b35???????? 8d85f8fdffff 50 ff7508 ffd6 59 } // n = 6, score = 100 // 8b35???????? | // 8d85f8fdffff | je 0x14 // 50 | push eax // ff7508 | push eax // ffd6 | lea eax, [ebp - 4] // 59 | push 4 $sequence_30 = { 8d8c2414080000 51 ffd3 5d 8b35???????? 6a01 } // n = 6, score = 100 // 8d8c2414080000 | push esi // 51 | push ebx // ffd3 | push 1 // 5d | push edi // 8b35???????? | // 6a01 | test esi, esi $sequence_31 = { 56 ba00020000 57 8bca 33c0 } // n = 5, score = 100 // 56 | push eax // ba00020000 | push edi // 57 | push eax // 8bca | pop ecx // 33c0 | test eax, eax $sequence_32 = { ff15???????? e8???????? e8???????? 53 ff15???????? 50 ff15???????? } // n = 7, score = 100 // ff15???????? | // e8???????? | // e8???????? | // 53 | je 0x14 // ff15???????? | // 50 | push eax // ff15???????? | condition: 7 of them and filesize < 74309632 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY