Actor(s): Lazarus Group
There is no description at this point.
rule win_pslogger_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.pslogger." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pslogger" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { e9???????? b910000000 ff15???????? 6685c0 7910 b914000000 ff15???????? } // n = 7, score = 300 // e9???????? | // b910000000 | mov ecx, 0x10 // ff15???????? | // 6685c0 | test ax, ax // 7910 | jns 0x12 // b914000000 | mov ecx, 0x14 // ff15???????? | $sequence_1 = { 4889842488000000 498bf9 498bd8 488bf2 } // n = 4, score = 300 // 4889842488000000 | lea edx, [esp + 0x20] // 498bf9 | dec eax // 498bd8 | mov ecx, ebp // 488bf2 | test eax, eax $sequence_2 = { 33d2 ff15???????? 488b0d???????? 33d2 ff15???????? 488b0d???????? } // n = 6, score = 300 // 33d2 | xor edx, edx // ff15???????? | // 488b0d???????? | // 33d2 | xor edx, edx // ff15???????? | // 488b0d???????? | $sequence_3 = { e8???????? b9b80b0000 e8???????? 33d2 41b8b80b0000 488bc8 4c8be0 } // n = 7, score = 300 // e8???????? | // b9b80b0000 | cmp ebx, edx // e8???????? | // 33d2 | je 0x24 // 41b8b80b0000 | dec eax // 488bc8 | mov ecx, dword ptr [ebx] // 4c8be0 | dec eax $sequence_4 = { 7406 ff15???????? 48891e 488bd3 488bcf } // n = 5, score = 300 // 7406 | inc ecx // ff15???????? | // 48891e | mov eax, 0xbb8 // 488bd3 | dec eax // 488bcf | mov ecx, eax $sequence_5 = { e8???????? 488d8c2480030000 e8???????? 488d542420 488bcd ff15???????? 85c0 } // n = 7, score = 300 // e8???????? | // 488d8c2480030000 | test ecx, ecx // e8???????? | // 488d542420 | je 0x12 // 488bcd | mov ecx, 0xbb8 // ff15???????? | // 85c0 | xor edx, edx $sequence_6 = { 483bc8 740e 4885c9 7406 ff15???????? } // n = 5, score = 300 // 483bc8 | test ecx, ecx // 740e | je 0xc // 4885c9 | dec eax // 7406 | cmp ecx, eax // ff15???????? | $sequence_7 = { 741f 488b0b 4885c9 740a } // n = 4, score = 300 // 741f | je 0x21 // 488b0b | dec eax // 4885c9 | mov ecx, dword ptr [ebx] // 740a | dec eax $sequence_8 = { 50 52 ffd6 eb76 } // n = 4, score = 100 // 50 | dec eax // 52 | test ecx, ecx // ffd6 | je 0xb // eb76 | dec eax $sequence_9 = { 8d842400070000 6808020000 6a00 50 e8???????? 83c40c 68b80b0000 } // n = 7, score = 100 // 8d842400070000 | mov edx, ebx // 6808020000 | dec eax // 6a00 | mov ecx, edi // 50 | dec eax // e8???????? | // 83c40c | cmp ecx, eax // 68b80b0000 | je 0x13 $sequence_10 = { 83c8ff 8d7c2434 83c40c b900010000 803d????????00 f3ab 0f85c6060000 } // n = 7, score = 100 // 83c8ff | lea eax, [esp + 0x700] // 8d7c2434 | push 0x208 // 83c40c | push 0 // b900010000 | push eax // 803d????????00 | // f3ab | add esp, 0xc // 0f85c6060000 | push 0xbb8 $sequence_11 = { 7e20 6690 8894373d1d0000 b801000000 8b0c9508784200 43 } // n = 6, score = 100 // 7e20 | push eax // 6690 | push edx // 8894373d1d0000 | call esi // b801000000 | jmp 0x7a // 8b0c9508784200 | xor eax, eax // 43 | nop dword ptr [eax] $sequence_12 = { 83c414 8d4e02 5f 660f1f440000 668b06 83c602 } // n = 6, score = 100 // 83c414 | mov edi, ecx // 8d4e02 | dec ecx // 5f | mov ebx, eax // 660f1f440000 | dec eax // 668b06 | mov esi, edx // 83c602 | dec eax $sequence_13 = { 8d8424f8040000 50 8d842494040000 50 8d842410090000 68???????? 50 } // n = 7, score = 100 // 8d8424f8040000 | add eax, 0x18 // 50 | dec eax // 8d842494040000 | cmp eax, ecx // 50 | jne 0xffffffe9 // 8d842410090000 | dec eax // 68???????? | // 50 | cmp ebx, ecx $sequence_14 = { 6689842430040000 e9???????? f30f7e05???????? a1???????? 660fd6842428040000 89842430040000 e9???????? } // n = 7, score = 100 // 6689842430040000 | mov byte ptr [eax + esi], al // e9???????? | // f30f7e05???????? | // a1???????? | // 660fd6842428040000 | inc eax // 89842430040000 | add esp, 0x14 // e9???????? | $sequence_15 = { 33c0 0f1f00 880430 40 } // n = 4, score = 100 // 33c0 | mov dword ptr [ebx], edi // 0f1f00 | dec eax // 880430 | mov dword ptr [esp + 0x88], eax // 40 | dec ecx condition: 7 of them and filesize < 475136 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY