SYMBOLCOMMON_NAMEaka. SYNONYMS
win.payload (Back to overview)

Payload

VTCollection    

According to EG-FinCIRT, Payload is a cross-platform ransomware family with native compiled binaries for Windows and Linux/ESXi, exposing rich command-line options that let operators tune targeting, performance, and anti-forensic behavior. The Windows variant aggressively prepares the system by deleting recovery points, stopping key services and processes, wiping or bypassing logging mechanisms, and optionally hiding and self-deleting its executable while running encryption in the background. Its core uses an offline hybrid cryptosystem combining Curve25519 key exchange with optimized ChaCha20 (using CPU feature detection and multithreading, plus partial encryption for large files) and appends an obfuscated metadata footer needed for decryption. The Linux/ESXi variant is a small stripped ELF binary that parses virtual machine inventory data to locate and encrypt VM disk files, focusing on efficient disruption of virtualized workloads with fewer ancillary features than the Windows version.

References
2026-05-05 ⋅ EG-FinCirt ⋅ EG-FinCirt Malware Analysis team
Payload Ransomware: In-depth technical analysis
Payload
Yara Rules
[TLP:WHITE] win_payload_auto (20260917 | Detects win.payload.)
rule win_payload_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.payload."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.payload"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 58 668907 eb15 8bc3 33d2 f7f1 }
            // n = 6, score = 100
            //   58                   | pop                 eax
            //   668907               | mov                 word ptr [edi], ax
            //   eb15                 | jmp                 0x17
            //   8bc3                 | mov                 eax, ebx
            //   33d2                 | xor                 edx, edx
            //   f7f1                 | div                 ecx

        $sequence_1 = { 13f2 0fa4ce01 89704c 03c9 894848 8bc5 f7eb }
            // n = 7, score = 100
            //   13f2                 | adc                 esi, edx
            //   0fa4ce01             | shld                esi, ecx, 1
            //   89704c               | mov                 dword ptr [eax + 0x4c], esi
            //   03c9                 | add                 ecx, ecx
            //   894848               | mov                 dword ptr [eax + 0x48], ecx
            //   8bc5                 | mov                 eax, ebp
            //   f7eb                 | imul                ebx

        $sequence_2 = { 85ff 7420 8b5d14 6a00 6a00 6a00 ff35???????? }
            // n = 7, score = 100
            //   85ff                 | test                edi, edi
            //   7420                 | je                  0x22
            //   8b5d14               | mov                 ebx, dword ptr [ebp + 0x14]
            //   6a00                 | push                0
            //   6a00                 | push                0
            //   6a00                 | push                0
            //   ff35????????         |                     

        $sequence_3 = { e8???????? 8b4500 5f 03c6 5e 5d 5b }
            // n = 7, score = 100
            //   e8????????           |                     
            //   8b4500               | mov                 eax, dword ptr [ebp]
            //   5f                   | pop                 edi
            //   03c6                 | add                 eax, esi
            //   5e                   | pop                 esi
            //   5d                   | pop                 ebp
            //   5b                   | pop                 ebx

        $sequence_4 = { 8b5508 8bc8 d1f9 2b14cd10b74400 7419 85d2 }
            // n = 6, score = 100
            //   8b5508               | mov                 edx, dword ptr [ebp + 8]
            //   8bc8                 | mov                 ecx, eax
            //   d1f9                 | sar                 ecx, 1
            //   2b14cd10b74400       | sub                 edx, dword ptr [ecx*8 + 0x44b710]
            //   7419                 | je                  0x1b
            //   85d2                 | test                edx, edx

        $sequence_5 = { 894ddc 894dec 8d4dc8 51 6800000080 8d4dec 8945d0 }
            // n = 7, score = 100
            //   894ddc               | mov                 dword ptr [ebp - 0x24], ecx
            //   894dec               | mov                 dword ptr [ebp - 0x14], ecx
            //   8d4dc8               | lea                 ecx, [ebp - 0x38]
            //   51                   | push                ecx
            //   6800000080           | push                0x80000000
            //   8d4dec               | lea                 ecx, [ebp - 0x14]
            //   8945d0               | mov                 dword ptr [ebp - 0x30], eax

        $sequence_6 = { 50 8d9558ffffff e8???????? 59 8b4dfc 5f 5e }
            // n = 7, score = 100
            //   50                   | push                eax
            //   8d9558ffffff         | lea                 edx, [ebp - 0xa8]
            //   e8????????           |                     
            //   59                   | pop                 ecx
            //   8b4dfc               | mov                 ecx, dword ptr [ebp - 4]
            //   5f                   | pop                 edi
            //   5e                   | pop                 esi

        $sequence_7 = { 745d 56 33f6 8d85f4fdffff 50 ffb6b82e4500 ff15???????? }
            // n = 7, score = 100
            //   745d                 | je                  0x5f
            //   56                   | push                esi
            //   33f6                 | xor                 esi, esi
            //   8d85f4fdffff         | lea                 eax, [ebp - 0x20c]
            //   50                   | push                eax
            //   ffb6b82e4500         | push                dword ptr [esi + 0x452eb8]
            //   ff15????????         |                     

        $sequence_8 = { 0fb6c3 99 8bf8 8a7d06 0fb64502 8bf2 }
            // n = 6, score = 100
            //   0fb6c3               | movzx               eax, bl
            //   99                   | cdq                 
            //   8bf8                 | mov                 edi, eax
            //   8a7d06               | mov                 bh, byte ptr [ebp + 6]
            //   0fb64502             | movzx               eax, byte ptr [ebp + 2]
            //   8bf2                 | mov                 esi, edx

        $sequence_9 = { 83f804 0f838c000000 885c05e8 40 83f804 7cf0 895dd8 }
            // n = 7, score = 100
            //   83f804               | cmp                 eax, 4
            //   0f838c000000         | jae                 0x92
            //   885c05e8             | mov                 byte ptr [ebp + eax - 0x18], bl
            //   40                   | inc                 eax
            //   83f804               | cmp                 eax, 4
            //   7cf0                 | jl                  0xfffffff2
            //   895dd8               | mov                 dword ptr [ebp - 0x28], ebx

    condition:
        7 of them and filesize < 837632
}
Download all Yara Rules