Actor(s): Winnti Umbrella
There is no description at this point.
rule win_pipemon_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.pipemon." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pipemon" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 48ffc1 4983e801 75ee 4983c128 } // n = 4, score = 100 // 48ffc1 | mov ecx, edi // 4983e801 | dec eax // 75ee | mov eax, dword ptr [edx + 8] // 4983c128 | dec eax $sequence_1 = { 4889442420 4183c9ff 4c8d8560040000 33d2 33c9 ff15???????? } // n = 6, score = 100 // 4889442420 | dec eax // 4183c9ff | sub esp, 0x20 // 4c8d8560040000 | inc esp // 33d2 | mov esi, ecx // 33c9 | dec esp // ff15???????? | $sequence_2 = { 4c89642430 895c2428 4889442420 4183c9ff 4c8d8560040000 33d2 33c9 } // n = 7, score = 100 // 4c89642430 | dec eax // 895c2428 | xor eax, esp // 4889442420 | dec eax // 4183c9ff | mov dword ptr [ebp + 0x47], eax // 4c8d8560040000 | dec eax // 33d2 | mov edi, ecx // 33c9 | dec eax $sequence_3 = { 8bc8 4903cc ff542428 8b7510 4c8bf8 448b7500 4903f4 } // n = 7, score = 100 // 8bc8 | je 0x393 // 4903cc | nop dword ptr [eax] // ff542428 | cmp dword ptr [ebp - 0x48], edi // 8b7510 | je 0x372 // 4c8bf8 | dec eax // 448b7500 | lea edx, [ebp - 0x50] // 4903f4 | dec eax $sequence_4 = { 488bc2 488d0d713a0100 48890b 488d5308 33c9 } // n = 5, score = 100 // 488bc2 | inc esp // 488d0d713a0100 | mov eax, dword ptr [ebx + 0x20] // 48890b | dec eax // 488d5308 | lea edx, [0x1f8ec] // 33c9 | dec eax $sequence_5 = { 41b880000000 488d8d60020000 e8???????? 488d542450 488d8d60020000 ff15???????? } // n = 6, score = 100 // 41b880000000 | mov eax, dword ptr [eax + 0x90] // 488d8d60020000 | movups xmmword ptr [ecx + 0x70], xmm0 // e8???????? | // 488d542450 | movups xmmword ptr [ecx + 0x80], xmm1 // 488d8d60020000 | dec eax // ff15???????? | $sequence_6 = { 488d153ac30000 b918000000 4c8d0526c30000 e8???????? 488bf8 4885c0 7412 } // n = 7, score = 100 // 488d153ac30000 | mov dword ptr [ebp + 0x78], edx // b918000000 | dec eax // 4c8d0526c30000 | inc edx // e8???????? | // 488bf8 | dec eax // 4885c0 | mov dword ptr [ebp + 0x88], eax // 7412 | dec eax $sequence_7 = { 74ed 488bd8 483b5c2440 e9???????? 0f1005???????? 0f1185d0010000 } // n = 6, score = 100 // 74ed | cmp ecx, ebx // 488bd8 | je 0xc7 // 483b5c2440 | dec eax // e9???????? | // 0f1005???????? | // 0f1185d0010000 | lea ebx, [0x1c9c6] $sequence_8 = { 488bc1 48c1f806 4c8d0550400100 83e23f 48c1e206 498b04c0 f644103801 } // n = 7, score = 100 // 488bc1 | dec eax // 48c1f806 | lea ecx, [0x136ed] // 4c8d0550400100 | dec eax // 83e23f | mov dword ptr [ebx], ecx // 48c1e206 | dec eax // 498b04c0 | lea edx, [ebx + 8] // f644103801 | xor ecx, ecx $sequence_9 = { 750c 4d8b36 4d85f6 0f8518feffff 488b6c2420 4c636d3c 33c9 } // n = 7, score = 100 // 750c | cmp eax, ecx // 4d8b36 | jb 0x8fc // 4d85f6 | inc dx // 0f8518feffff | inc cx // 488b6c2420 | cmp edx, ebx // 4c636d3c | jb 0x7fa // 33c9 | mov ecx, dword ptr [ebx + ecx*8 + 0x28] condition: 7 of them and filesize < 389120 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY