SYMBOLCOMMON_NAMEaka. SYNONYMS
win.rising_sun (Back to overview)

Rising Sun

Actor(s): Operation Sharpshooter

VTCollection    

There is no description at this point.

References
2022-03-31 ⋅ APNIC ⋅ Debashis Pal
How to: Detect and prevent common data exfiltration attacks
Agent Tesla DNSMessenger PingBack Rising Sun
2020-02-13 ⋅ Qianxin ⋅ Qi Anxin Threat Intelligence Center
APT Report 2019
Chrysaor Exodus Dacls VPNFilter DNSRat Griffon KopiLuwak More_eggs SQLRat AppleJeus BONDUPDATER Agent.BTZ Anchor AndroMut AppleJeus BOOSTWRITE Brambul Carbanak Cobalt Strike Dacls DistTrack DNSpionage Dtrack ELECTRICFISH FlawedAmmyy FlawedGrace Get2 Grateful POS HOPLIGHT Imminent Monitor RAT jason Joanap KerrDown KEYMARBLE Lambert LightNeuron LoJax MiniDuke PolyglotDuke PowerRatankba Rising Sun SDBbot ServHelper Snatch Stuxnet TinyMet tRat TrickBot Volgmer X-Agent Zebrocy
2018-12-12 ⋅ McAfee ⋅ Asheer Malhotra, Ryan Sherstobitoff
Operation Sharpshooter: Campaign Targets Global Defense, Critical Infrastructure
Rising Sun
2018-12-12 ⋅ McAfee ⋅ Asheer Malhotra, Ryan Sherstobitoff
‘Operation Sharpshooter’ Targets Global Defense, Critical Infrastructure
Rising Sun Lazarus Group Operation Sharpshooter
Yara Rules
[TLP:WHITE] win_rising_sun_auto (20260917 | Detects win.rising_sun.)
rule win_rising_sun_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.rising_sun."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.rising_sun"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { c74424784569b2a9 c744247c7c51995a c7458078713ca7 c745842ac83026 c74588e7278dd6 c7458cbb39ea4b c7459001c2880b }
            // n = 7, score = 100
            //   c74424784569b2a9     | repne scasd         eax, dword ptr es:[edi]
            //   c744247c7c51995a     | dec                 eax
            //   c7458078713ca7       | arpl                bx, ax
            //   c745842ac83026       | add                 ebx, 2
            //   c74588e7278dd6       | dec                 eax
            //   c7458cbb39ea4b       | or                  ecx, 0xffffffff
            //   c7459001c2880b       | xor                 eax, eax

        $sequence_1 = { 488d0db5b80000 e8???????? 90 4585e4 740f b908000000 }
            // n = 6, score = 100
            //   488d0db5b80000       | lea                 edx, [edi + 0x1020]
            //   e8????????           |                     
            //   90                   | dec                 esp
            //   4585e4               | lea                 ecx, [esp + 0x40]
            //   740f                 | inc                 ecx
            //   b908000000           | mov                 eax, 4

        $sequence_2 = { c7858c000000c53d497f c78590000000bf84166f c7859400000024f814a4 c785980000003ccf7613 c7859c00000076cbbdc4 c785a00000000a578186 c785a4000000ded26ee1 }
            // n = 7, score = 100
            //   c7858c000000c53d497f     | test    edx, edx
            //   c78590000000bf84166f     | jne    0x596
            //   c7859400000024f814a4     | dec    eax
            //   c785980000003ccf7613     | mov    ecx, ebp
            //   c7859c00000076cbbdc4     | dec    eax
            //   c785a00000000a578186     | mov    ebx, eax
            //   c785a4000000ded26ee1     | dec    eax

        $sequence_3 = { cc b90e000780 e8???????? cc 48d1ef 498bcf }
            // n = 6, score = 100
            //   cc                   | mov                 ebx, esi
            //   b90e000780           | dec                 eax
            //   e8????????           |                     
            //   cc                   | mov                 edi, dword ptr [esp + 0x28]
            //   48d1ef               | dec                 eax
            //   498bcf               | lea                 ecx, [esp + 0x30]

        $sequence_4 = { 48894518 4d8bf8 488bfa 488bd9 498bc8 e8???????? 48837b1000 }
            // n = 7, score = 100
            //   48894518             | dec                 ecx
            //   4d8bf8               | mov                 eax, dword ptr [esp]
            //   488bfa               | mov                 edx, 0x11
            //   488bd9               | dec                 eax
            //   498bc8               | mov                 ecx, edi
            //   e8????????           |                     
            //   48837b1000           | mov                 ecx, eax

        $sequence_5 = { c7442424b8ffe7e7 c7442428f02933e8 c744242c7e0b296c c744243001968b7d }
            // n = 4, score = 100
            //   c7442424b8ffe7e7     | lea                 ecx, [ebp + 0xc10]
            //   c7442428f02933e8     | dec                 eax
            //   c744242c7e0b296c     | lea                 edx, [0x149ca]
            //   c744243001968b7d     | dec                 eax

        $sequence_6 = { 488d8dd25d0000 0f44d0 4863c3 33ff 42881438 }
            // n = 5, score = 100
            //   488d8dd25d0000       | dec                 eax
            //   0f44d0               | arpl                di, ax
            //   4863c3               | test                edi, edi
            //   33ff                 | jne                 0x80
            //   42881438             | dec                 ecx

        $sequence_7 = { 83c302 48f7d1 8d3c09 4863cb 448bc7 4903cf }
            // n = 6, score = 100
            //   83c302               | dec                 eax
            //   48f7d1               | xor                 eax, esp
            //   8d3c09               | dec                 eax
            //   4863cb               | mov                 dword ptr [ebp + 0x1b90], eax
            //   448bc7               | dec                 eax
            //   4903cf               | mov                 edi, ecx

        $sequence_8 = { 0fb705???????? 895587 668945ef 488b05???????? c745bf2677725f 488945f7 0fb605???????? }
            // n = 7, score = 100
            //   0fb705????????       |                     
            //   895587               | mov                 dword ptr [esp + 0x22], ebx
            //   668945ef             | dec                 esp
            //   488b05????????       |                     
            //   c745bf2677725f       | mov                 dword ptr [esp + 0x20], ebx
            //   488945f7             | dec                 eax
            //   0fb605????????       |                     

        $sequence_9 = { 488905???????? ff15???????? 488bc8 ff15???????? 488d15748c0000 }
            // n = 5, score = 100
            //   488905????????       |                     
            //   ff15????????         |                     
            //   488bc8               | jmp                 0x4c7
            //   ff15????????         |                     
            //   488d15748c0000       | inc                 ecx

    condition:
        7 of them and filesize < 409600
}
Download all Yara Rules