SYMBOLCOMMON_NAMEaka. SYNONYMS
win.sakula_rat (Back to overview)

Sakula RAT

aka: Sakurel

Actor(s): APT 26, Hurricane Panda

VTCollection    

Sakula / Sakurel is a trojan horse that opens a back door and downloads potentially malicious files onto the compromised computer.

References
2022-05-24 ⋅ Malwarebytes ⋅ Threat Intelligence Team
Unknown APT group has targeted Russia repeatedly since Ukraine invasion
Sakula RAT
2018-11-16 ⋅ CyberThreatIntelligence Blog ⋅ Action09
(C)0ld Case : From Aerospace to China’s interests.
Sakula RAT
2016-07-14 ⋅ Github (nccgroup) ⋅ NCC Group PLC
Technical Notes on Sakula
Sakula RAT
2015-08-06 ⋅ Symantec ⋅ Jon DiMaggio
The Black Vine cyberespionage group
Sakula RAT APT19
2015-07-30 ⋅ Secureworks ⋅ Dell Secureworks CTU
Sakula Malware Family
Sakula RAT
2015-02-06 ⋅ CrowdStrike ⋅ CrowdStrike
CrowdStrike Global Threat Intel Report 2014
BlackPOS CryptoLocker Derusbi Elise Enfal EvilGrab Gameover P2P HttpBrowser MedusaHTTP Mirage Naikon NetTraveler pirpi PlugX Poison Ivy Sakula RAT Sinowal sykipot taidoor
2014-02-23 ⋅ Symantec ⋅ Symantec
Trojan.Sakurel
Sakula RAT
2014-02-21 ⋅ SonicWall ⋅ Ed Miles
CVE 2014-0322 Malware - Sakurel (Feb 21, 2014)
Sakula RAT
Yara Rules
[TLP:WHITE] win_sakula_rat_auto (20260917 | Detects win.sakula_rat.)
rule win_sakula_rat_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.sakula_rat."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sakula_rat"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 6a00 6800010000 6a00 6a00 68???????? }
            // n = 5, score = 300
            //   6a00                 | dec                 eax
            //   6800010000           | mov                 ecx, dword ptr [esp + 0x50]
            //   6a00                 | lea                 edx, [ebx + 0x40]
            //   6a00                 | dec                 eax
            //   68????????           |                     

        $sequence_1 = { 85c0 7407 b801000000 eb2c e8???????? 83f804 7d07 }
            // n = 7, score = 200
            //   85c0                 | add                 al, 0x61
            //   7407                 | mov                 byte ptr [ecx], al
            //   b801000000           | cmp                 eax, 0
            //   eb2c                 | je                  0x64
            //   e8????????           |                     
            //   83f804               | push                0x400
            //   7d07                 | mov                 dword ptr [ebp - 0x10], eax

        $sequence_2 = { 5e 8a4801 40 84c9 75f8 8b15???????? 8a0d???????? }
            // n = 7, score = 200
            //   5e                   | rep movsd           dword ptr es:[edi], dword ptr [esi]
            //   8a4801               | mov                 ecx, eax
            //   40                   | and                 ecx, 3
            //   84c9                 | lea                 eax, [ebx + 0x96]
            //   75f8                 | rep movsb           byte ptr es:[edi], byte ptr [esi]
            //   8b15????????         |                     
            //   8a0d????????         |                     

        $sequence_3 = { 6a00 68???????? e8???????? 68fa000000 6a00 68???????? }
            // n = 6, score = 200
            //   6a00                 | je                  2
            //   68????????           |                     
            //   e8????????           |                     
            //   68fa000000           | push                dword ptr [ebp - 4]
            //   6a00                 | pop                 edx
            //   68????????           |                     

        $sequence_4 = { 84c9 75f9 2bc6 8d7c0002 57 e8???????? }
            // n = 6, score = 200
            //   84c9                 | push                0
            //   75f9                 | push                1
            //   2bc6                 | call                edi
            //   8d7c0002             | test                eax, eax
            //   57                   | test                eax, eax
            //   e8????????           |                     

        $sequence_5 = { 56 6a00 6a01 ffd7 85c0 }
            // n = 5, score = 200
            //   56                   | je                  0x16
            //   6a00                 | mov                 dl, 0x1a
            //   6a01                 | div                 dl
            //   ffd7                 | and                 eax, 0xff00
            //   85c0                 | shr                 eax, 8

        $sequence_6 = { 8bf1 57 56 8bc6 e8???????? 83c404 33c0 }
            // n = 7, score = 200
            //   8bf1                 | push                1
            //   57                   | call                edi
            //   56                   | push                0
            //   8bc6                 | push                0
            //   e8????????           |                     
            //   83c404               | push                eax
            //   33c0                 | push                ebx

        $sequence_7 = { f3a5 8bc8 83e103 8d8396000000 f3a4 8bc8 }
            // n = 6, score = 200
            //   f3a5                 | push                0
            //   8bc8                 | push                0
            //   83e103               | push                0
            //   8d8396000000         | push                0xfa
            //   f3a4                 | push                0
            //   8bc8                 | push                esi

        $sequence_8 = { 83f800 745f 6800040000 e8???????? 8945f0 }
            // n = 5, score = 100
            //   83f800               | add                 eax, 0x10
            //   745f                 | push                eax
            //   6800040000           | push                dword ptr [ebp - 4]
            //   e8????????           |                     
            //   8945f0               | push                0x104

        $sequence_9 = { e8???????? 4c8d4dc7 4c8d05a01d0000 488d0da90e0000 488bd3 }
            // n = 5, score = 100
            //   e8????????           |                     
            //   4c8d4dc7             | mov                 dword ptr [ebp - 0x54], 1
            //   4c8d05a01d0000       | dec                 esp
            //   488d0da90e0000       | lea                 ecx, [ebp - 0x39]
            //   488bd3               | dec                 esp

        $sequence_10 = { 7414 b21a f6f2 2500ff0000 c1e808 0461 8801 }
            // n = 7, score = 100
            //   7414                 | push                0x100
            //   b21a                 | push                0
            //   f6f2                 | push                0
            //   2500ff0000           | push                eax
            //   c1e808               | push                dword ptr [ebp - 0x1c]
            //   0461                 | push                dword ptr [ebp - 4]
            //   8801                 | mov                 eax, dword ptr [ebp - 8]

        $sequence_11 = { 488b4dc7 4c8b45cf 488b55d7 488b01 488364242000 4c8d0d240f0000 }
            // n = 6, score = 100
            //   488b4dc7             | dec                 eax
            //   4c8b45cf             | mov                 edx, ebx
            //   488b55d7             | mov                 edx, 8
            //   488b01               | dec                 eax
            //   488364242000         | mov                 ecx, esi
            //   4c8d0d240f0000       | dec                 eax

        $sequence_12 = { ff15???????? 8364242800 488364242000 4c8bc6 448bc8 33d2 }
            // n = 6, score = 100
            //   ff15????????         |                     
            //   8364242800           | lea                 edx, [ebx + 0x40]
            //   488364242000         | dec                 eax
            //   4c8bc6               | test                eax, eax
            //   448bc8               | je                  0xc5
            //   33d2                 | dec                 eax

        $sequence_13 = { 50 ff75e4 e8???????? ff75fc e8???????? 8b45f8 }
            // n = 6, score = 100
            //   50                   | mov                 ecx, dword ptr [esp + 0x58]
            //   ff75e4               | dec                 esp
            //   e8????????           |                     
            //   ff75fc               | mov                 eax, esi
            //   e8????????           |                     
            //   8b45f8               | xor                 edx, edx

        $sequence_14 = { ff15???????? 85c0 7427 488b4c2450 8d5340 }
            // n = 5, score = 100
            //   ff15????????         |                     
            //   85c0                 | mov                 ebx, eax
            //   7427                 | dec                 eax
            //   488b4c2450           | mov                 ecx, dword ptr [ebp - 0x39]
            //   8d5340               | dec                 esp

        $sequence_15 = { e9???????? 6a00 e8???????? 83f801 0f8509010000 6804010000 }
            // n = 6, score = 100
            //   e9????????           |                     
            //   6a00                 | and                 dword ptr [esp + 0x20], 0
            //   e8????????           |                     
            //   83f801               | dec                 esp
            //   0f8509010000         | mov                 eax, esi
            //   6804010000           | inc                 esp

        $sequence_16 = { ba08000000 ff15???????? 488bce 488bd8 ff15???????? }
            // n = 5, score = 100
            //   ba08000000           | lea                 eax, [0x1da0]
            //   ff15????????         |                     
            //   488bce               | dec                 eax
            //   488bd8               | lea                 ecx, [0xea9]
            //   ff15????????         |                     

        $sequence_17 = { 50 ff75fc e8???????? ff75f8 e8???????? ff75ec }
            // n = 6, score = 100
            //   50                   | mov                 ecx, eax
            //   ff75fc               | xor                 edx, edx
            //   e8????????           |                     
            //   ff75f8               | mov                 dword ptr [ebx], edi
            //   e8????????           |                     
            //   ff75ec               | mov                 dword ptr [ebx + 0x14], 4

        $sequence_18 = { 4c8bc6 33d2 448bc8 33c9 }
            // n = 4, score = 100
            //   4c8bc6               | test                eax, eax
            //   33d2                 | je                  0x29
            //   448bc8               | dec                 eax
            //   33c9                 | mov                 ecx, dword ptr [esp + 0x50]

        $sequence_19 = { 33d2 41b8ce070000 c744247068000000 c745ac01000000 }
            // n = 4, score = 100
            //   33d2                 | xor                 edx, edx
            //   41b8ce070000         | inc                 ecx
            //   c744247068000000     | mov                 eax, 0x7ce
            //   c745ac01000000       | mov                 dword ptr [esp + 0x70], 0x68

        $sequence_20 = { 4885c0 0f84bf000000 488bc8 ff15???????? 85c0 }
            // n = 5, score = 100
            //   4885c0               | mov                 eax, dword ptr [ebp - 0x31]
            //   0f84bf000000         | dec                 eax
            //   488bc8               | mov                 edx, dword ptr [ebp - 0x29]
            //   ff15????????         |                     
            //   85c0                 | dec                 eax

        $sequence_21 = { 83c010 50 ff75fc e8???????? 6804010000 e8???????? 8945dc }
            // n = 7, score = 100
            //   83c010               | inc                 esp
            //   50                   | mov                 ecx, eax
            //   ff75fc               | xor                 ecx, ecx
            //   e8????????           |                     
            //   6804010000           | and                 dword ptr [esp + 0x28], 0
            //   e8????????           |                     
            //   8945dc               | dec                 eax

        $sequence_22 = { 7400 ff75fc e8???????? 5a }
            // n = 4, score = 100
            //   7400                 | cmp                 eax, esi
            //   ff75fc               | je                  0x9f
            //   e8????????           |                     
            //   5a                   | push                0

    condition:
        7 of them and filesize < 229376
}
[TLP:WHITE] win_sakula_rat_w0   (20170517 | Sakula v1.0)
/*
    This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as    long as you use it under this license.

*/
rule win_sakula_rat_w0 {
    meta:
        description = "Sakula v1.0"
        date = "2015-10-13"
        author = "Airbus Defence and Space Cybersecurity CSIRT - Yoann Francou"
		source = "https://github.com/mattulm/sfiles_yara/blob/master/malware/Sakula.yar"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sakula_rat"
        malpedia_version = "20170517"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
    strings:
        $m1 = "%d_of_%d_for_%s_on_%s"
        $m2 = "/c ping 127.0.0.1 & del /q \"%s\""
        $m3 = "=%s&type=%d"
        $m4 = "?photoid="
        $m5 = "iexplorer"
                $m6 = "net start \"%s\""
        $v1_1 = "MicroPlayerUpdate.exe"

    condition:
        all of ($m*) and not $v1_1
}
[TLP:WHITE] win_sakula_rat_w1   (20170517 | Sakula v1.1)
/*
    This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as    long as you use it under this license.

*/

rule win_sakula_rat_w1 {
    meta:
        description = "Sakula v1.1"
        date = "2015-10-13"
        author = "Airbus Defence and Space Cybersecurity CSIRT - Yoann Francou"
		source = "https://github.com/mattulm/sfiles_yara/blob/master/malware/Sakula.yar"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sakula_rat"
        malpedia_version = "20170517"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
    strings:
        $m1 = "%d_of_%d_for_%s_on_%s"
        $m2 = "/c ping 127.0.0.1 & del /q \"%s\""
        $m3 = "=%s&type=%d"
        $m4 = "?photoid="
        $m5 = "iexplorer"
                $m6 = "net start \"%s\""
        $v1_1 = "MicroPlayerUpdate.exe"

    condition:
        all of them
}
[TLP:WHITE] win_sakula_rat_w2   (20170517 | Sakula v1.2)
/*
    This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as    long as you use it under this license.

*/


rule win_sakula_rat_w2 {
    meta:
        description = "Sakula v1.2"
        date = "2015-10-13"
        author = "Airbus Defence and Space Cybersecurity CSIRT - Yoann Francou"
		source = "https://github.com/mattulm/sfiles_yara/blob/master/malware/Sakula.yar"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sakula_rat"
        malpedia_version = "20170517"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
    strings:
        $m1 = "%d_of_%d_for_%s_on_%s"
        $m2 = "/c ping 127.0.0.1 & del /q \"%s\""
        $m3 = "cmd.exe /c rundll32 \"%s\""
        $v1_1 = "MicroPlayerUpdate.exe"
        $v1_2 = "CCPUpdate"

    condition:
        $m1 and $m2 and $m3 and $v1_2 and not $v1_1
}
[TLP:WHITE] win_sakula_rat_w3   (20170517 | Sakula v1.3)
/*
    This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as    long as you use it under this license.

*/


rule win_sakula_rat_w3 {
    meta:
        description = "Sakula v1.3"
        date = "2015-10-13"
        author = "Airbus Defence and Space Cybersecurity CSIRT - Yoann Francou"
		source = "https://github.com/mattulm/sfiles_yara/blob/master/malware/Sakula.yar"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sakula_rat"
        malpedia_version = "20170517"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
    strings:
        $m1 = "%d_of_%d_for_%s_on_%s"
        $m2 = "/c ping 127.0.0.1 & del /q \"%s\""
        $m3 = "cmd.exe /c rundll32 \"%s\""

        $v1_3 = { 81 3E 78 03 00 00 75 57  8D 54 24 14 52 68 0C 05 41 00 68 01 00 00 80 FF  15 00 F0 40 00 85 C0 74 10 8B 44 24 14 68 2C 31  41 00 50 FF 15 10 F0 40 00 8B 4C 24 14 51 FF 15  24 F0 40 00 E8 0F 09 00 }

    condition:
        all of them
}
[TLP:WHITE] win_sakula_rat_w4   (20170517 | Sakula v1.4)
/*
    This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as    long as you use it under this license.

*/

rule win_sakula_rat_w4 {
    meta:
        description = "Sakula v1.4"
        date = "2015-10-13"
        author = "Airbus Defence and Space Cybersecurity CSIRT - Yoann Francou"
		source = "https://github.com/mattulm/sfiles_yara/blob/master/malware/Sakula.yar"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sakula_rat"
        malpedia_version = "20170517"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
    strings:
        $m1 = "%d_of_%d_for_%s_on_%s"
        $m2 = "/c ping 127.0.0.1 & del /q \"%s\""
        $m3 = "cmd.exe /c rundll32 \"%s\""

        $v1_4 = { 50 E8 CD FC FF FF 83 C4  04 68 E8 03 00 00 FF D7 56 E8 54 12 00 00 E9 AE  FE FF FF E8 13 F5 FF FF }

    condition:
        all of them
}
Download all Yara Rules