Actor(s): RansomHub
Ransomware written in Golang and obfuscated with Gobfuscate, with significant code overlap to Knight ransomware.
rule win_ransomhub_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.ransomhub." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ransomhub" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 48ffc3 90 4939db 7365 4c898424d0000000 4c89e8 4c89d9 } // n = 7, score = 100 // 48ffc3 | mov dword ptr [esp + 0x48], edi // 90 | dec esp // 4939db | mov dword ptr [esp + 0xb0], eax // 7365 | dec esp // 4c898424d0000000 | mov dword ptr [esp + 0x50], ecx // 4c89e8 | mov byte ptr [esp + 0x2e], bl // 4c89d9 | inc eax $sequence_1 = { 488d0515dd1200 e8???????? 833d????????00 750e 488b8c24202b0000 48894818 eb11 } // n = 7, score = 100 // 488d0515dd1200 | movzx edi, byte ptr [esp + 0x110] // e8???????? | // 833d????????00 | // 750e | inc esp // 488b8c24202b0000 | mov byte ptr [esp + 0xb2], bh // 48894818 | inc esp // eb11 | movzx edi, byte ptr [esp + 0x111] $sequence_2 = { e8???????? 4889c1 4889df 488d0549052f00 488b5c2438 0f1f4000 e8???????? } // n = 7, score = 100 // e8???????? | // 4889c1 | xor edi, edi // 4889df | dec eax // 488d0549052f00 | mov dword ptr [esp + 0x60], 0 // 488b5c2438 | mov eax, 6 // 0f1f4000 | mov ecx, 0x28 // e8???????? | $sequence_3 = { 8854242b 0fb654241c 0fb674241f 31f2 8854242c 0fb654241e 4129d7 } // n = 7, score = 100 // 8854242b | dec eax // 0fb654241c | mov ecx, dword ptr [esp + 0x498] // 0fb674241f | dec eax // 31f2 | lea edi, [0x31ae43] // 8854242c | dec eax // 0fb654241e | mov dword ptr [esp + 0x490], eax // 4129d7 | dec eax $sequence_4 = { e8???????? 488b6d00 488b8c2400010000 488b9424f8000000 4883f90e 7e4f 48be03ce445067fcb5d4 } // n = 7, score = 100 // e8???????? | // 488b6d00 | jae 0x1dd9 // 488b8c2400010000 | mov edi, 1 // 488b9424f8000000 | dec eax // 4883f90e | lea esi, [0xbada0] // 7e4f | dec eax // 48be03ce445067fcb5d4 | mov edi, dword ptr [esp + 0x180] $sequence_5 = { eb09 4889c7 90 e8???????? 488d0514f22e00 488b5c2438 488d0d6b903300 } // n = 7, score = 100 // eb09 | mov byte ptr [esp + 0x47], bl // 4889c7 | dec esp // 90 | mov eax, edx // e8???????? | // 488d0514f22e00 | mov edi, 1 // 488b5c2438 | dec eax // 488d0d6b903300 | lea esi, [0x20d3bb] $sequence_6 = { e8???????? 4c89e0 4c89e9 e8???????? 4c89e9 4889da e8???????? } // n = 7, score = 100 // e8???????? | // 4c89e0 | dec ecx // 4c89e9 | mov ecx, edx // e8???????? | // 4c89e9 | dec eax // 4889da | sar edx, 0x3f // e8???????? | $sequence_7 = { 493b6610 0f86bf000000 4883ec38 48896c2430 488d6c2430 48ba6162f35d4d2e0b6e 488954241a } // n = 7, score = 100 // 493b6610 | dec eax // 0f86bf000000 | mov dword ptr [esp + 0x508], ebx // 4883ec38 | dec eax // 48896c2430 | mov dword ptr [esp + 0x2250], ecx // 488d6c2430 | dec eax // 48ba6162f35d4d2e0b6e | lea eax, [0x122d23] // 488954241a | nop dword ptr [eax] $sequence_8 = { e8???????? 488d1d3c9a1900 4889c1 488d3d12941b00 488b742428 488d05e6633f00 e8???????? } // n = 7, score = 100 // e8???????? | // 488d1d3c9a1900 | cmp ecx, 1 // 4889c1 | jbe 0x1bd8 // 488d3d12941b00 | nop // 488b742428 | inc ebp // 488d05e6633f00 | movzx esp, word ptr [edx + edx] // e8???????? | $sequence_9 = { 88542455 0fb654242c 0fb674242a 01f2 88542456 0fb6542422 4131d7 } // n = 7, score = 100 // 88542455 | mov eax, dword ptr [edx + 0x68] // 0fb654242c | dec ebp // 0fb674242a | test eax, eax // 01f2 | je 0xfeb // 88542456 | dec ebp // 0fb6542422 | mov ecx, dword ptr [eax + 0x20] // 4131d7 | dec eax condition: 7 of them and filesize < 12821504 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY