SYMBOLCOMMON_NAMEaka. SYNONYMS
win.railsetter (Back to overview)

RAILSETTER

VTCollection    

According to Trend Micro, RAILSETTER is a persistence installer component designed to work with RAILLOAD. Its main functions include: Copying and renaming RAILLOAD’s intended host from System32 to the intended target directory; Timestomping RAILLOAD and its host’s create, access, and modify time; Creating a scheduled task for persistence.

References
2025-03-31 ⋅ Trend Micro ⋅ Lenart Bermejo, Ted Lee, Theo Chen
The Espionage Toolkit of Earth Alux: A Closer Look at its Advanced Techniques
Godzilla Webshell Cobalt Strike FINALDRAFT RAILSETTER Earth Alux
Yara Rules
[TLP:WHITE] win_railsetter_auto (20260917 | Detects win.railsetter.)
rule win_railsetter_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.railsetter."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.railsetter"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 498bcf e8???????? 488bc8 0fb754247e e8???????? }
            // n = 5, score = 100
            //   498bcf               | dec                 eax
            //   e8????????           |                     
            //   488bc8               | lea                 edx, [0x4ba9b]
            //   0fb754247e           | dec                 eax
            //   e8????????           |                     

        $sequence_1 = { e9???????? 488d8ae8020000 e9???????? 488d8ab0020000 e9???????? 488d8a70010000 e9???????? }
            // n = 7, score = 100
            //   e9????????           |                     
            //   488d8ae8020000       | mov                 ecx, esi
            //   e9????????           |                     
            //   488d8ab0020000       | test                eax, eax
            //   e9????????           |                     
            //   488d8a70010000       | dec                 eax
            //   e9????????           |                     

        $sequence_2 = { 488b9540070000 4c8d0573300100 498bce e8???????? 85c0 7461 e9???????? }
            // n = 7, score = 100
            //   488b9540070000       | lea                 edx, [0x5151e]
            //   4c8d0573300100       | dec                 ecx
            //   498bce               | mov                 ecx, edi
            //   e8????????           |                     
            //   85c0                 | dec                 eax
            //   7461                 | mov                 ecx, eax
            //   e9????????           |                     

        $sequence_3 = { 488d4c2420 ff15???????? 85c0 7418 ff15???????? 8bc8 2b4c2424 }
            // n = 7, score = 100
            //   488d4c2420           | dec                 eax
            //   ff15????????         |                     
            //   85c0                 | lea                 ebp, [eax - 0x478]
            //   7418                 | dec                 eax
            //   ff15????????         |                     
            //   8bc8                 | sub                 esp, 0x540
            //   2b4c2424             | movaps              xmmword ptr [eax - 0x48], xmm6

        $sequence_4 = { 410fb608 83e10f 4a0fbe8419587e0400 428a8c19687e0400 4c2bc0 418b40fc d3e8 }
            // n = 7, score = 100
            //   410fb608             | je                  0xfffffb02
            //   83e10f               | dec                 eax
            //   4a0fbe8419587e0400     | mov    ecx, dword ptr [ebp + 0x40]
            //   428a8c19687e0400     | dec                 eax
            //   4c2bc0               | lea                 edx, [0x1d082]
            //   418b40fc             | dec                 eax
            //   d3e8                 | cmp                 dword ptr [ecx], ebx

        $sequence_5 = { 498bd5 48c1e506 48c1fa06 4c8d1dffa60200 4889542440 498b04d3 4484442838 }
            // n = 7, score = 100
            //   498bd5               | xor                 eax, eax
            //   48c1e506             | dec                 eax
            //   48c1fa06             | mov                 edx, esi
            //   4c8d1dffa60200       | dec                 eax
            //   4889542440           | lea                 ecx, [ebp - 0x41]
            //   498b04d3             | dec                 eax
            //   4484442838           | mov                 dword ptr [ebp - 0x41], eax

        $sequence_6 = { 498bca 488b4030 ff15???????? 85c0 7405 83e801 7557 }
            // n = 7, score = 100
            //   498bca               | ja                  0x4f4
            //   488b4030             | dec                 ecx
            //   ff15????????         |                     
            //   85c0                 | mov                 ecx, eax
            //   7405                 | xor                 eax, eax
            //   83e801               | jmp                 0x4ac
            //   7557                 | dec                 ecx

        $sequence_7 = { 482bd7 4c3bc2 0f87a6000000 4885ff 750c 498bc0 4883c420 }
            // n = 7, score = 100
            //   482bd7               | mov                 edx, 0x19
            //   4c3bc2               | inc                 esp
            //   0f87a6000000         | mov                 ecx, edx
            //   4885ff               | inc                 ebp
            //   750c                 | lea                 eax, [edi + 0x1e]
            //   498bc0               | dec                 eax
            //   4883c420             | lea                 ecx, [0x4959b]

        $sequence_8 = { 8b5598 e8???????? 488bc8 488d15e2ec0400 e8???????? 488bc8 8b559c }
            // n = 7, score = 100
            //   8b5598               | dec                 eax
            //   e8????????           |                     
            //   488bc8               | lea                 edx, [0x4da95]
            //   488d15e2ec0400       | dec                 eax
            //   e8????????           |                     
            //   488bc8               | mov                 ecx, eax
            //   8b559c               | dec                 eax

        $sequence_9 = { 4533c0 488d1d85aefdff 458bc8 4c8bd9 418a03 413a8419889c0400 740a }
            // n = 7, score = 100
            //   4533c0               | lea                 edx, [0x5192a]
            //   488d1d85aefdff       | dec                 eax
            //   458bc8               | mov                 ecx, eax
            //   4c8bd9               | mov                 edx, esi
            //   418a03               | dec                 eax
            //   413a8419889c0400     | mov                 ecx, eax
            //   740a                 | dec                 eax

    condition:
        7 of them and filesize < 866304
}
Download all Yara Rules