SYMBOLCOMMON_NAMEaka. SYNONYMS
win.sappycache (Back to overview)

SappyCache

VTCollection    

There is no description at this point.

References
2019-08-05 ⋅ Reversing Labs ⋅ Tomislav Pericin
Catching lateral movement in internal emails
SappyCache
2019-08-01 ⋅ ClearSky ⋅ ClearSky Cyber Security
2019 H1 Cyber Events Summary Report
EVILNUM Cardinal RAT SappyCache
2019-03-27 ⋅ ⋅ ESTsecurity ⋅ Alyac
Lazarus Group APT Counterattack Against Israeli Military
SappyCache
2019-03-27 ⋅ ⋅ Alyac
라자루스(Lazarus) 그룹, 이스라엘 군수업체 대상 APT 역습
SappyCache
2019-03-26 ⋅ FireEye ⋅ Dileep Kumar Jallepalli
WinRAR Zero-day Abused in Multiple Campaigns
SappyCache
Yara Rules
[TLP:WHITE] win_sappycache_auto (20260917 | Detects win.sappycache.)
rule win_sappycache_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.sappycache."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sappycache"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { f6c101 7412 b9c1000000 ff15???????? 33c0 e9???????? 410fb74614 }
            // n = 7, score = 200
            //   f6c101               | mov                 dword ptr [esp + 0x24], ecx
            //   7412                 | dec                 eax
            //   b9c1000000           | cmp                 edx, ebx
            //   ff15????????         |                     
            //   33c0                 | ja                  0x2b0
            //   e9????????           |                     
            //   410fb74614           | dec                 eax

        $sequence_1 = { 7509 418b4e38 f6c101 7412 b9c1000000 ff15???????? 33c0 }
            // n = 7, score = 200
            //   7509                 | dec                 ecx
            //   418b4e38             | add                 eax, ecx
            //   f6c101               | jmp                 0x20e
            //   7412                 | mov                 eax, dword ptr [edx]
            //   b9c1000000           | add                 eax, ecx
            //   ff15????????         |                     
            //   33c0                 | dec                 eax

        $sequence_2 = { 8bea 0f1f8000000000 e8???????? 448bf0 }
            // n = 4, score = 200
            //   8bea                 | dec                 eax
            //   0f1f8000000000       | lea                 ecx, [ebx + 0x48]
            //   e8????????           |                     
            //   448bf0               | test                eax, eax

        $sequence_3 = { 488bcf ff15???????? 33c0 488bac2480000000 488b5c2478 488bbc2488000000 488b4c2450 }
            // n = 7, score = 200
            //   488bcf               | lea                 eax, [esp + 0x60]
            //   ff15????????         |                     
            //   33c0                 | dec                 eax
            //   488bac2480000000     | lea                 edx, [0x11a27]
            //   488b5c2478           | dec                 eax
            //   488bbc2488000000     | lea                 ecx, [esp + 0x60]
            //   488b4c2450           | xor                 eax, eax

        $sequence_4 = { 33db 4c8bfa 4c8be1 4883fa40 7312 b90d000000 }
            // n = 6, score = 200
            //   33db                 | lea                 eax, [0x138d8]
            //   4c8bfa               | dec                 ecx
            //   4c8be1               | ror                 ecx, cl
            //   4883fa40             | cmp                 eax, 1
            //   7312                 | sete                al
            //   b90d000000           | jmp                 0x5a7

        $sequence_5 = { 33d2 488d4d40 41b800010000 e8???????? 33d2 488d8d40010000 41b800010000 }
            // n = 7, score = 200
            //   33d2                 | arpl                cx, cx
            //   488d4d40             | dec                 eax
            //   41b800010000         | lea                 edx, [0xe430]
            //   e8????????           |                     
            //   33d2                 | test                ecx, ecx
            //   488d8d40010000       | js                  0x666
            //   41b800010000         | jae                 0x660

        $sequence_6 = { e9???????? 4d3bc1 0f84a3000000 8b7500 498b9cf720860100 4885db 7407 }
            // n = 7, score = 200
            //   e9????????           |                     
            //   4d3bc1               | test                eax, eax
            //   0f84a3000000         | jne                 0x50
            //   8b7500               | dec                 eax
            //   498b9cf720860100     | lea                 edx, [0x11a13]
            //   4885db               | dec                 ecx
            //   7407                 | mov                 ecx, esp

        $sequence_7 = { 754c 488d15131a0100 498bcc ff15???????? 488d15631a0100 488d0d4c610100 ff15???????? }
            // n = 7, score = 200
            //   754c                 | dec                 eax
            //   488d15131a0100       | mov                 esi, ebx
            //   498bcc               | dec                 eax
            //   ff15????????         |                     
            //   488d15631a0100       | sar                 esi, 6
            //   488d0d4c610100       | dec                 eax
            //   ff15????????         |                     

        $sequence_8 = { 482be0 488b05???????? 4833c4 48898520620000 4c89442468 }
            // n = 5, score = 200
            //   482be0               | mov                 ecx, edi
            //   488b05????????       |                     
            //   4833c4               | je                  0x29e
            //   48898520620000       | dec                 eax
            //   4c89442468           | mov                 ecx, dword ptr [esp + 0x30]

        $sequence_9 = { 488d05133c0100 ffcb 488d0c9b 488d0cc8 ff15???????? ff0d???????? 85db }
            // n = 7, score = 200
            //   488d05133c0100       | mov                 dword ptr [esp + 0x90], edi
            //   ffcb                 | inc                 ecx
            //   488d0c9b             | shl                 al, 4
            //   488d0cc8             | inc                 esp
            //   ff15????????         |                     
            //   ff0d????????         |                     
            //   85db                 | or                  al, al

    condition:
        7 of them and filesize < 262144
}
Download all Yara Rules