There is no description at this point.
rule win_sathurbot_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.sathurbot." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sathurbot" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 890424 c7442404???????? ff15???????? 83ec10 85c0 0f94c0 837c242400 } // n = 7, score = 100 // 890424 | mov dword ptr [esp], eax // c7442404???????? | // ff15???????? | // 83ec10 | sub esp, 0x10 // 85c0 | test eax, eax // 0f94c0 | sete al // 837c242400 | cmp dword ptr [esp + 0x24], 0 $sequence_1 = { f6c101 b8e4a22b29 b93cdfaf6e 0f45c1 e9???????? a1???????? 8d48ff } // n = 7, score = 100 // f6c101 | test cl, 1 // b8e4a22b29 | mov eax, 0x292ba2e4 // b93cdfaf6e | mov ecx, 0x6eafdf3c // 0f45c1 | cmovne eax, ecx // e9???????? | // a1???????? | // 8d48ff | lea ecx, [eax - 1] $sequence_2 = { f6c701 bb94f5b5ea bf8b98173b 0f45df e9???????? 81ff54cf23f0 89fb } // n = 7, score = 100 // f6c701 | test bh, 1 // bb94f5b5ea | mov ebx, 0xeab5f594 // bf8b98173b | mov edi, 0x3b17988b // 0f45df | cmovne ebx, edi // e9???????? | // 81ff54cf23f0 | cmp edi, 0xf023cf54 // 89fb | mov ebx, edi $sequence_3 = { bbdf9a40cb bf07720b13 ba8836551d 0f85c1f7ffff 8b4e2c 83ec08 c744240400000000 } // n = 7, score = 100 // bbdf9a40cb | mov ebx, 0xcb409adf // bf07720b13 | mov edi, 0x130b7207 // ba8836551d | mov edx, 0x1d553688 // 0f85c1f7ffff | jne 0xfffff7c7 // 8b4e2c | mov ecx, dword ptr [esi + 0x2c] // 83ec08 | sub esp, 8 // c744240400000000 | mov dword ptr [esp + 4], 0 $sequence_4 = { f6c101 0f94c0 813d????????0a000000 0f9cc1 08c1 b87737df95 b9bc0dd317 } // n = 7, score = 100 // f6c101 | test cl, 1 // 0f94c0 | sete al // 813d????????0a000000 | // 0f9cc1 | setl cl // 08c1 | or cl, al // b87737df95 | mov eax, 0x95df3777 // b9bc0dd317 | mov ecx, 0x17d30dbc $sequence_5 = { eb9a 8a45ee 8a4def 08c1 f6c101 b85d04e70e b9146a4ff8 } // n = 7, score = 100 // eb9a | jmp 0xffffff9c // 8a45ee | mov al, byte ptr [ebp - 0x12] // 8a4def | mov cl, byte ptr [ebp - 0x11] // 08c1 | or cl, al // f6c101 | test cl, 1 // b85d04e70e | mov eax, 0xee7045d // b9146a4ff8 | mov ecx, 0xf84f6a14 $sequence_6 = { e9???????? 8a45e6 84c0 b8e109b7d8 b9259f9ef5 e9???????? 8b450c } // n = 7, score = 100 // e9???????? | // 8a45e6 | mov al, byte ptr [ebp - 0x1a] // 84c0 | test al, al // b8e109b7d8 | mov eax, 0xd8b709e1 // b9259f9ef5 | mov ecx, 0xf59e9f25 // e9???????? | // 8b450c | mov eax, dword ptr [ebp + 0xc] $sequence_7 = { f6c101 0f94c0 813d????????0a000000 0f9cc1 08c1 b84f581604 b9df112848 } // n = 7, score = 100 // f6c101 | test cl, 1 // 0f94c0 | sete al // 813d????????0a000000 | // 0f9cc1 | setl cl // 08c1 | or cl, al // b84f581604 | mov eax, 0x416584f // b9df112848 | mov ecx, 0x482811df $sequence_8 = { f6c101 0f94c0 813d????????0a000000 0f9cc1 08c1 b87a79be99 b9330fabc2 } // n = 7, score = 100 // f6c101 | test cl, 1 // 0f94c0 | sete al // 813d????????0a000000 | // 0f9cc1 | setl cl // 08c1 | or cl, al // b87a79be99 | mov eax, 0x99be797a // b9330fabc2 | mov ecx, 0xc2ab0f33 $sequence_9 = { 8d4818 8b4648 50 e8???????? 83ec04 8b4624 890424 } // n = 7, score = 100 // 8d4818 | lea ecx, [eax + 0x18] // 8b4648 | mov eax, dword ptr [esi + 0x48] // 50 | push eax // e8???????? | // 83ec04 | sub esp, 4 // 8b4624 | mov eax, dword ptr [esi + 0x24] // 890424 | mov dword ptr [esp], eax condition: 7 of them and filesize < 2727936 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY