SYMBOLCOMMON_NAMEaka. SYNONYMS
win.sappycache (Back to overview)

SappyCache


There is no description at this point.

References
2019-08-05Reversing LabsTomislav Pericin
@online{pericin:20190805:catching:4aeb984, author = {Tomislav Pericin}, title = {{Catching lateral movement in internal emails}}, date = {2019-08-05}, organization = {Reversing Labs}, url = {https://blog.reversinglabs.com/blog/catching-lateral-movement-in-internal-emails}, language = {English}, urldate = {2020-07-15} } Catching lateral movement in internal emails
SappyCache
2019-08ClearSkyClearSky Cyber Security
@techreport{security:201908:2019:716d69e, author = {ClearSky Cyber Security}, title = {{2019 H1 Cyber Events Summary Report}}, date = {2019-08}, institution = {ClearSky}, url = {https://www.clearskysec.com/wp-content/uploads/2019/08/ClearSky-2019-H1-Cyber-Events-Summary-Report.pdf}, language = {English}, urldate = {2020-06-29} } 2019 H1 Cyber Events Summary Report
EVILNUM Cardinal RAT SappyCache
2019-03-27ESTsecurityAlyac
@online{alyac:20190327:lazarus:df092d7, author = {Alyac}, title = {{Lazarus Group APT Counterattack Against Israeli Military}}, date = {2019-03-27}, organization = {ESTsecurity}, url = {https://blog.alyac.co.kr/2219}, language = {Korean}, urldate = {2020-06-29} } Lazarus Group APT Counterattack Against Israeli Military
SappyCache
2019-03-27Alyac
@online{alyac:20190327:lazarus:2172304, author = {Alyac}, title = {{라자루스(Lazarus) 그룹, 이스라엘 군수업체 대상 APT 역습}}, date = {2019-03-27}, url = {https://blog.alyac.co.kr/m/2219}, language = {Korean}, urldate = {2020-07-15} } 라자루스(Lazarus) 그룹, 이스라엘 군수업체 대상 APT 역습
SappyCache
2019-03-26FireEyeDileep Kumar Jallepalli
@online{jallepalli:20190326:winrar:dff4878, author = {Dileep Kumar Jallepalli}, title = {{WinRAR Zero-day Abused in Multiple Campaigns}}, date = {2019-03-26}, organization = {FireEye}, url = {https://www.fireeye.com/blog/threat-research/2019/03/winrar-zero-day-abused-in-multiple-campaigns.html}, language = {English}, urldate = {2019-12-20} } WinRAR Zero-day Abused in Multiple Campaigns
SappyCache
Yara Rules
[TLP:WHITE] win_sappycache_auto (20221125 | Detects win.sappycache.)
rule win_sappycache_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2022-11-21"
        version = "1"
        description = "Detects win.sappycache."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sappycache"
        malpedia_rule_date = "20221118"
        malpedia_hash = "e0702e2e6d1d00da65c8a29a4ebacd0a4c59e1af"
        malpedia_version = "20221125"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4883ec20 488d1d16150100 488d350f150100 eb16 488b3b 4885ff }
            // n = 6, score = 200
            //   4883ec20             | dec                 eax
            //   488d1d16150100       | lea                 ecx, [eax + ebp]
            //   488d350f150100       | dec                 eax
            //   eb16                 | mov                 esi, eax
            //   488b3b               | dec                 eax
            //   4885ff               | test                ebx, ebx

        $sequence_1 = { 488d8d40010000 41b800010000 e8???????? ba00000200 }
            // n = 4, score = 200
            //   488d8d40010000       | dec                 eax
            //   41b800010000         | mov                 esi, dword ptr [esp + 0x48]
            //   e8????????           |                     
            //   ba00000200           | dec                 eax

        $sequence_2 = { 4883faff 750a 488bcb e8???????? eb0f 488bd3 488d0dcb490100 }
            // n = 7, score = 200
            //   4883faff             | lea                 edx, [0x11a27]
            //   750a                 | dec                 eax
            //   488bcb               | lea                 ecx, [esp + 0x60]
            //   e8????????           |                     
            //   eb0f                 | xor                 eax, eax
            //   488bd3               | inc                 ecx
            //   488d0dcb490100       | mov                 edi, ecx

        $sequence_3 = { ff15???????? 488bf0 4883f8ff 7515 33c0 488b4c2450 }
            // n = 6, score = 200
            //   ff15????????         |                     
            //   488bf0               | shr                 dl, 2
            //   4883f8ff             | shr                 al, 6
            //   7515                 | inc                 eax
            //   33c0                 | and                 bh, 0x3f
            //   488b4c2450           | or                  bl, al

        $sequence_4 = { c74500f4010000 488bce ff15???????? 4983cfff 488d8540020000 498bd7 660f1f440000 }
            // n = 7, score = 200
            //   c74500f4010000       | js                  0x329
            //   488bce               | dec                 eax
            //   ff15????????         |                     
            //   4983cfff             | cwde                
            //   488d8540020000       | dec                 eax
            //   498bd7               | cmp                 eax, 0xe4
            //   660f1f440000         | jae                 0x329

        $sequence_5 = { 488bfb 4885db 75d9 8d4b0e ff15???????? }
            // n = 5, score = 200
            //   488bfb               | ja                  0x9d2
            //   4885db               | dec                 eax
            //   75d9                 | lea                 ebx, [edi + 0x48]
            //   8d4b0e               | dec                 eax
            //   ff15????????         |                     

        $sequence_6 = { 488d9520420000 498bce ff15???????? 8b5580 b940000000 }
            // n = 5, score = 200
            //   488d9520420000       | dec                 eax
            //   498bce               | mov                 dword ptr [edx], ecx
            //   ff15????????         |                     
            //   8b5580               | dec                 eax
            //   b940000000           | mov                 dword ptr [edx + 8], ecx

        $sequence_7 = { e8???????? 85c0 7407 b902000000 cd29 488d0d434b0100 }
            // n = 6, score = 200
            //   e8????????           |                     
            //   85c0                 | lea                 ecx, [eax + 0x40]
            //   7407                 | dec                 eax
            //   b902000000           | add                 ecx, 8
            //   cd29                 | dec                 eax
            //   488d0d434b0100       | cmp                 ecx, ebx

        $sequence_8 = { 41b800800000 488bce ff15???????? 4885db 742b 0f1f4000 488b4b08 }
            // n = 7, score = 200
            //   41b800800000         | and                 al, 3
            //   488bce               | and                 bl, 0xf
            //   ff15????????         |                     
            //   4885db               | inc                 ecx
            //   742b                 | shl                 al, 4
            //   0f1f4000             | inc                 esp
            //   488b4b08             | or                  al, al

        $sequence_9 = { 6644392c50 75f6 4c8d4db0 4533c0 488d8d40020000 }
            // n = 5, score = 200
            //   6644392c50           | dec                 eax
            //   75f6                 | mov                 ebx, edi
            //   4c8d4db0             | dec                 eax
            //   4533c0               | test                edi, edi
            //   488d8d40020000       | jne                 0x1477

    condition:
        7 of them and filesize < 262144
}
Download all Yara Rules