SYMBOLCOMMON_NAMEaka. SYNONYMS
win.rifdoor (Back to overview)

Rifdoor

Actor(s): Lazarus Group, Silent Chollima

VTCollection    

There is no description at this point.

References
2020-04-16 ⋅ VMWare Carbon Black ⋅ Scott Knight
The Evolution of Lazarus
HOTCROISSANT Rifdoor
2020-03-03 ⋅ PWC UK ⋅ PWC UK
Cyber Threats 2019:A Year in Retrospect
KevDroid MESSAGETAP magecart AndroMut Cobalt Strike CobInt Crimson RAT DNSpionage Dridex Dtrack Emotet FlawedAmmyy FlawedGrace FriedEx Gandcrab Get2 GlobeImposter Grateful POS ISFB Kazuar LockerGoga Nokki QakBot Ramnit REvil Rifdoor RokRAT Ryuk shadowhammer ShadowPad Shifu Skipper StoneDrill Stuxnet TrickBot Winnti ZeroCleare APT41 MUSTANG PANDA Sea Turtle
2018-06-23 ⋅ AhnLab ⋅ AhnLab
Full Discloser of Andariel, A Subgroup of Lazarus Threat Group
PhanDoor Rifdoor
2017-05-01 ⋅ IssueMakersLab ⋅ IssueMakersLab
Operation GoldenAxe
Rifdoor
2017-01-01 ⋅ FSI ⋅ Kay Kwak (Kyoung-Ju Kwak)
Campaign Rifle: Andariel, The Maiden of Anguish
Rifdoor
Yara Rules
[TLP:WHITE] win_rifdoor_auto (20260917 | Detects win.rifdoor.)
rule win_rifdoor_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.rifdoor."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rifdoor"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 3bf7 7cc8 5b 8bc6 5e 5d 59 }
            // n = 7, score = 200
            //   3bf7                 | cmp                 esi, edi
            //   7cc8                 | jl                  0xffffffca
            //   5b                   | pop                 ebx
            //   8bc6                 | mov                 eax, esi
            //   5e                   | pop                 esi
            //   5d                   | pop                 ebp
            //   59                   | pop                 ecx

        $sequence_1 = { b940000000 32db 3bc1 7d0e 885c301c 017e5c 8b465c }
            // n = 7, score = 200
            //   b940000000           | mov                 ecx, 0x40
            //   32db                 | xor                 bl, bl
            //   3bc1                 | cmp                 eax, ecx
            //   7d0e                 | jge                 0x10
            //   885c301c             | mov                 byte ptr [eax + esi + 0x1c], bl
            //   017e5c               | add                 dword ptr [esi + 0x5c], edi
            //   8b465c               | mov                 eax, dword ptr [esi + 0x5c]

        $sequence_2 = { e8???????? 83c40c 55 57 ffd6 a3???????? 895c2410 }
            // n = 7, score = 200
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc
            //   55                   | push                ebp
            //   57                   | push                edi
            //   ffd6                 | call                esi
            //   a3????????           |                     
            //   895c2410             | mov                 dword ptr [esp + 0x10], ebx

        $sequence_3 = { 33c9 8b540c2c 3b91541d4100 7513 83e804 83c104 83f804 }
            // n = 7, score = 200
            //   33c9                 | xor                 ecx, ecx
            //   8b540c2c             | mov                 edx, dword ptr [esp + ecx + 0x2c]
            //   3b91541d4100         | cmp                 edx, dword ptr [ecx + 0x411d54]
            //   7513                 | jne                 0x15
            //   83e804               | sub                 eax, 4
            //   83c104               | add                 ecx, 4
            //   83f804               | cmp                 eax, 4

        $sequence_4 = { 8d442410 50 8d4314 b9???????? 895c2414 e8???????? }
            // n = 6, score = 200
            //   8d442410             | lea                 eax, [esp + 0x10]
            //   50                   | push                eax
            //   8d4314               | lea                 eax, [ebx + 0x14]
            //   b9????????           |                     
            //   895c2414             | mov                 dword ptr [esp + 0x14], ebx
            //   e8????????           |                     

        $sequence_5 = { 75f1 8d442404 6a12 50 e8???????? }
            // n = 5, score = 200
            //   75f1                 | jne                 0xfffffff3
            //   8d442404             | lea                 eax, [esp + 4]
            //   6a12                 | push                0x12
            //   50                   | push                eax
            //   e8????????           |                     

        $sequence_6 = { c744241801000000 8d542410 52 b810000000 }
            // n = 4, score = 200
            //   c744241801000000     | mov                 dword ptr [esp + 0x18], 1
            //   8d542410             | lea                 edx, [esp + 0x10]
            //   52                   | push                edx
            //   b810000000           | mov                 eax, 0x10

        $sequence_7 = { 83f93d 7468 83f920 7505 b92b000000 0fbf0c4db81d4100 }
            // n = 6, score = 200
            //   83f93d               | cmp                 ecx, 0x3d
            //   7468                 | je                  0x6a
            //   83f920               | cmp                 ecx, 0x20
            //   7505                 | jne                 7
            //   b92b000000           | mov                 ecx, 0x2b
            //   0fbf0c4db81d4100     | movsx               ecx, word ptr [ecx*2 + 0x411db8]

        $sequence_8 = { 52 8d45e8 50 8d8de8f7ffff }
            // n = 4, score = 100
            //   52                   | push                edx
            //   8d45e8               | lea                 eax, [ebp - 0x18]
            //   50                   | push                eax
            //   8d8de8f7ffff         | lea                 ecx, [ebp - 0x818]

        $sequence_9 = { 83c40c 8d8d68fcffff 51 8d9574fcffff 52 6a00 }
            // n = 6, score = 100
            //   83c40c               | add                 esp, 0xc
            //   8d8d68fcffff         | lea                 ecx, [ebp - 0x398]
            //   51                   | push                ecx
            //   8d9574fcffff         | lea                 edx, [ebp - 0x38c]
            //   52                   | push                edx
            //   6a00                 | push                0

        $sequence_10 = { 83c103 51 ffd3 a3???????? eb2c 8b14b7 83c203 }
            // n = 7, score = 100
            //   83c103               | add                 ecx, 3
            //   51                   | push                ecx
            //   ffd3                 | call                ebx
            //   a3????????           |                     
            //   eb2c                 | jmp                 0x2e
            //   8b14b7               | mov                 edx, dword ptr [edi + esi*4]
            //   83c203               | add                 edx, 3

        $sequence_11 = { 68ff000000 e8???????? 59 59 8b7508 8d34f5000d4100 391e }
            // n = 7, score = 100
            //   68ff000000           | push                0xff
            //   e8????????           |                     
            //   59                   | pop                 ecx
            //   59                   | pop                 ecx
            //   8b7508               | mov                 esi, dword ptr [ebp + 8]
            //   8d34f5000d4100       | lea                 esi, [esi*8 + 0x410d00]
            //   391e                 | cmp                 dword ptr [esi], ebx

        $sequence_12 = { b9843a0000 81fb843a0000 7702 8bcb 2bd9 be2c1a0000 33ff }
            // n = 7, score = 100
            //   b9843a0000           | mov                 ecx, 0x3a84
            //   81fb843a0000         | cmp                 ebx, 0x3a84
            //   7702                 | ja                  4
            //   8bcb                 | mov                 ecx, ebx
            //   2bd9                 | sub                 ebx, ecx
            //   be2c1a0000           | mov                 esi, 0x1a2c
            //   33ff                 | xor                 edi, edi

        $sequence_13 = { eb08 ff15???????? 33c9 b873b2e745 f72d???????? }
            // n = 5, score = 100
            //   eb08                 | jmp                 0xa
            //   ff15????????         |                     
            //   33c9                 | xor                 ecx, ecx
            //   b873b2e745           | mov                 eax, 0x45e7b273
            //   f72d????????         |                     

        $sequence_14 = { ff15???????? 8bf8 83ffff 0f84bb000000 53 }
            // n = 5, score = 100
            //   ff15????????         |                     
            //   8bf8                 | mov                 edi, eax
            //   83ffff               | cmp                 edi, -1
            //   0f84bb000000         | je                  0xc1
            //   53                   | push                ebx

        $sequence_15 = { c785e4bcffff44000000 899d1cbdffff c78510bdffff01010000 66898514bdffff 33f6 8d642400 8d8d40bdffff }
            // n = 7, score = 100
            //   c785e4bcffff44000000     | mov    dword ptr [ebp - 0x431c], 0x44
            //   899d1cbdffff         | mov                 dword ptr [ebp - 0x42e4], ebx
            //   c78510bdffff01010000     | mov    dword ptr [ebp - 0x42f0], 0x101
            //   66898514bdffff       | mov                 word ptr [ebp - 0x42ec], ax
            //   33f6                 | xor                 esi, esi
            //   8d642400             | lea                 esp, [esp]
            //   8d8d40bdffff         | lea                 ecx, [ebp - 0x42c0]

    condition:
        7 of them and filesize < 212992
}
[TLP:WHITE] win_rifdoor_w0   (20230118 | detect_rifdoor)
rule win_rifdoor_w0 {
	meta:
	    description = "detect_rifdoor"
	    author = "@malgamy12"
	    date = "2022/11/11"
	    license = "DRL 1.1"
        hash1 = "19b2144927bd071e30df9fce5f3d49f1"
        hash2 = "d8ba4b4bfc5e0877fa8e8c1b26876ea6"
        hash3 = "d94d6f773c0ed5514d3e571e4b3681ba"
        hash4 = "5aca1e4ec64ba417d1b0ebea88bdd06e"
        hash5 = "45f8d44cba70520ca2ea97427ddaab3e"
        hash6 = "d3b2956904bed8c8146b8bb556b8911a"
        hash7 = "e4c4c9abdd8613afa17f58d721039a46"
        hash8 = "cf847663a7a9d6ddbe3a1f0d5e5236b6"
        hash9 = "01a0b932d82ed3b78ccfb2bb5826c32f"
        hash10 = "c6687e1fab97b2d7433a5e51fcf2aa30"

        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rifdoor"
        malpedia_rule_date = "20230118"
        malpedia_hash = ""
        malpedia_version = "20230118"
        malpedia_license = "DRL 1.1"
        malpedia_sharing = "TLP:WHITE"

    strings:
        $pdb = "rifle.pdb" ascii

        $s1 = "MUTEX394039_4830023" ascii
        $s2 = "CMD:%s %s %d/%d/%d %d:%d:%d" ascii
	$s3 = "/c del /q \"%s\" >> NUL" ascii

        $chunk_1 = {80 32 ?? 41 80 39 ?? 8B D1 75} // xor operation

        
    condition:
        uint16(0) == 0x5A4D  and ($pdb  or  (2 of ($s*) and $chunk_1 ))

}
Download all Yara Rules