There is no description at this point.
rule win_polyglot_ransom_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.polyglot_ransom." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.polyglot_ransom" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 746f 6e 3130 207269 6768745f6275 7474 6f } // n = 7, score = 100 // 746f | je 0x71 // 6e | outsb dx, byte ptr [esi] // 3130 | xor dword ptr [eax], esi // 207269 | and byte ptr [edx + 0x69], dh // 6768745f6275 | push 0x75625f74 // 7474 | je 0x76 // 6f | outsd dx, dword ptr [esi] $sequence_1 = { 69726563742064 65706f 7369 7420 746f 206269 } // n = 6, score = 100 // 69726563742064 | imul esi, dword ptr [edx + 0x65], 0x64207463 // 65706f | jo 0x72 // 7369 | jae 0x6b // 7420 | je 0x22 // 746f | je 0x71 // 206269 | and byte ptr [edx + 0x69], ah $sequence_2 = { 8d45c0 50 8d450c 50 e8???????? 53 53 } // n = 7, score = 100 // 8d45c0 | lea eax, [ebp - 0x40] // 50 | push eax // 8d450c | lea eax, [ebp + 0xc] // 50 | push eax // e8???????? | // 53 | push ebx // 53 | push ebx $sequence_3 = { eb02 32c9 84c9 7410 0fb6d9 80eb3d 80f924 } // n = 7, score = 100 // eb02 | jmp 4 // 32c9 | xor cl, cl // 84c9 | test cl, cl // 7410 | je 0x12 // 0fb6d9 | movzx ebx, cl // 80eb3d | sub bl, 0x3d // 80f924 | cmp cl, 0x24 $sequence_4 = { 6e 2e69742f27293b223e 50 61 7261 206162 7269 } // n = 7, score = 100 // 6e | outsb dx, byte ptr [esi] // 2e69742f27293b223e | imul esi, dword ptr cs:[edi + ebp + 0x27], 0x3e223b29 // 50 | push eax // 61 | popal // 7261 | jb 0x63 // 206162 | and byte ptr [ecx + 0x62], ah // 7269 | jb 0x6b $sequence_5 = { 653d226d6172 67696e3a2030223e 0d0a3c6831 3ed0a2d0b5d181 d182d0bed0b2 d0b0d18f20d1 80d0b0 } // n = 7, score = 100 // 653d226d6172 | cmp eax, 0x72616d22 // 67696e3a2030223e | imul ebp, dword ptr [bp + 0x3a], 0x3e223020 // 0d0a3c6831 | or eax, 0x31683c0a // 3ed0a2d0b5d181 | shl byte ptr ds:[edx - 0x7e2e4a30], 1 // d182d0bed0b2 | rol dword ptr [edx - 0x4d2f4130], 1 // d0b0d18f20d1 | sal byte ptr [eax - 0x2edf702f], 1 // 80d0b0 | adc al, 0xb0 $sequence_6 = { 3b22 3e42 61 636b3c 2f 61 3e0d0a3c7370 } // n = 7, score = 100 // 3b22 | cmp esp, dword ptr [edx] // 3e42 | inc edx // 61 | popal // 636b3c | arpl word ptr [ebx + 0x3c], bp // 2f | das // 61 | popal // 3e0d0a3c7370 | or eax, 0x70733c0a $sequence_7 = { 59 0f84f6000000 8b5b50 8b03 8d4dec 51 68???????? } // n = 7, score = 100 // 59 | pop ecx // 0f84f6000000 | je 0xfc // 8b5b50 | mov ebx, dword ptr [ebx + 0x50] // 8b03 | mov eax, dword ptr [ebx] // 8d4dec | lea ecx, [ebp - 0x14] // 51 | push ecx // 68???????? | $sequence_8 = { b8???????? e8???????? c645e441 c645e542 c645e643 c645e744 c645e859 } // n = 7, score = 100 // b8???????? | // e8???????? | // c645e441 | mov byte ptr [ebp - 0x1c], 0x41 // c645e542 | mov byte ptr [ebp - 0x1b], 0x42 // c645e643 | mov byte ptr [ebp - 0x1a], 0x43 // c645e744 | mov byte ptr [ebp - 0x19], 0x44 // c645e859 | mov byte ptr [ebp - 0x18], 0x59 $sequence_9 = { 760b fe4d55 dc35???????? 75f5 385d56 7502 d9e0 } // n = 7, score = 100 // 760b | jbe 0xd // fe4d55 | dec byte ptr [ebp + 0x55] // dc35???????? | // 75f5 | jne 0xfffffff7 // 385d56 | cmp byte ptr [ebp + 0x56], bl // 7502 | jne 4 // d9e0 | fchs condition: 7 of them and filesize < 1392640 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY