There is no description at this point.
rule win_proto8_rat_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.proto8_rat." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.proto8_rat" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { c747203f000000 488b4f28 488d2d97440400 483bcd 7442 4885c9 7405 } // n = 7, score = 100 // c747203f000000 | mov eax, 0xfffffffd // 488b4f28 | jmp 0x7df // 488d2d97440400 | mov eax, 0xfffffffe // 483bcd | jmp 0x7df // 7442 | or eax, 0xffffffff // 4885c9 | dec eax // 7405 | add esp, 0x58 $sequence_1 = { 897328 4885d2 741a 4863432c 85c0 7e0a 488bc8 } // n = 7, score = 100 // 897328 | dec eax // 4885d2 | add esp, 0x48 // 741a | ret // 4863432c | test eax, eax // 85c0 | jle 0x5b4 // 7e0a | test eax, eax // 488bc8 | je 0x5b6 $sequence_2 = { 741c 4489642420 41b940000000 4c8d4308 488b13 488bc8 e8???????? } // n = 7, score = 100 // 741c | dec eax // 4489642420 | cmp eax, 0x1f // 41b940000000 | ja 0xa84 // 4c8d4308 | jb 0x563 // 488b13 | dec eax // 488bc8 | add edx, 0x27 // e8???????? | $sequence_3 = { eb07 4863c2 498b04c1 486393f0000000 4963c8 48ffca 4823d1 } // n = 7, score = 100 // eb07 | dec ecx // 4863c2 | mov ebx, dword ptr [ebx + 0x18] // 498b04c1 | dec ecx // 486393f0000000 | mov esi, dword ptr [ebx + 0x20] // 4963c8 | dec ecx // 48ffca | mov edi, dword ptr [ebx + 0x28] // 4823d1 | dec ecx $sequence_4 = { f20f104c2438 f20f114810 b001 eb02 32c0 488b9c2480000000 4883c440 } // n = 7, score = 100 // f20f104c2438 | dec eax // f20f114810 | mov edx, edi // b001 | dec esp // eb02 | mov eax, dword ptr [edi + 0x18] // 32c0 | test eax, eax // 488b9c2480000000 | mov eax, 0xffffffdb // 4883c440 | test eax, eax $sequence_5 = { c3 4589b760020000 4889742448 48897c2458 498bcd e8???????? 898424a0000000 } // n = 7, score = 100 // c3 | mov edx, dword ptr [eax] // 4589b760020000 | dec eax // 4889742448 | test edx, edx // 48897c2458 | je 0x929 // 498bcd | dec eax // e8???????? | // 898424a0000000 | mov edx, dword ptr [edx] $sequence_6 = { e9???????? 85c0 7532 488d154e9f0400 488d4c2420 e8???????? 90 } // n = 7, score = 100 // e9???????? | // 85c0 | cwde // 7532 | inc esp // 488d154e9f0400 | cmp byte ptr [ebx + 0x41], ch // 488d4c2420 | je 0x106b // e8???????? | // 90 | dec esp $sequence_7 = { e8???????? 488b4b08 e8???????? 48892b ff8f20030000 48ffc6 4883c328 } // n = 7, score = 100 // e8???????? | // 488b4b08 | mov dword ptr [esp + 0x28], ebx // e8???????? | // 48892b | cmp eax, esi // ff8f20030000 | ret // 48ffc6 | dec eax // 4883c328 | lea eax, [0x55cc9] $sequence_8 = { 81e1ffffff0f 741e 8b06 25ffffff0f 3bc1 7513 488b4320 } // n = 7, score = 100 // 81e1ffffff0f | dec eax // 741e | mov esi, dword ptr [esp + 0x70] // 8b06 | dec esp // 25ffffff0f | mov eax, esi // 3bc1 | jne 0x520 // 7513 | dec eax // 488b4320 | mov dword ptr [esp + 0x30], ebx $sequence_9 = { b801000000 874360 4c8b01 488bd5 41ff5020 488b07 } // n = 6, score = 100 // b801000000 | sub edx, 1 // 874360 | jne 0xb7c // 4c8b01 | jmp 0xb8f // 488bd5 | dec eax // 41ff5020 | arpl dx, ax // 488b07 | nop condition: 7 of them and filesize < 2537472 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY