SYMBOLCOMMON_NAMEaka. SYNONYMS
win.shifu (Back to overview)

Shifu

VTCollection    

Shifu was originally discovered by Trusteer security researchers (Ilya Kolmanovich, Denis Laskov) in the middle of 2015. It is a banking trojan mostly focusing on Japanese banks and has rich features for remote data extraction and control.

References
2021-09-03 ⋅ Trend Micro ⋅ Mohamad Mokbel
The State of SSL/TLS Certificate Usage in Malware C&C Communications
AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
2020-05-21 ⋅ Intel 471 ⋅ Intel 471
A brief history of TA505
AndroMut Bart Dridex FlawedAmmyy FlawedGrace Gandcrab Get2 GlobeImposter Jaff Kegotip Locky Necurs Philadephia Ransom Pony QuantLoader Rockloader SDBbot ServHelper Shifu Snatch TrickBot
2020-03-03 ⋅ PWC UK ⋅ PWC UK
Cyber Threats 2019:A Year in Retrospect
KevDroid MESSAGETAP magecart AndroMut Cobalt Strike CobInt Crimson RAT DNSpionage Dridex Dtrack Emotet FlawedAmmyy FlawedGrace FriedEx Gandcrab Get2 GlobeImposter Grateful POS ISFB Kazuar LockerGoga Nokki QakBot Ramnit REvil Rifdoor RokRAT Ryuk shadowhammer ShadowPad Shifu Skipper StoneDrill Stuxnet TrickBot Winnti ZeroCleare APT41 MUSTANG PANDA Sea Turtle
2017-01-06 ⋅ Palo Alto Networks Unit 42 ⋅ Dominik Reichel
2016 Updates to Shifu Banking Trojan
Shifu
2015-11-02 ⋅ Virus Bulletin ⋅ Floser Bacurio Jr., Wayne Low
Shifu – the rise of a self-destructive banking trojan
Shifu
2015-08-31 ⋅ SecurityIntelligence ⋅ Denis Laskov, Ilya Kolmanovich, Limor Kessem
Shifu: ‘Masterful’ New Banking Trojan Is Attacking 14 Japanese Banks
Shifu
Yara Rules
[TLP:WHITE] win_shifu_auto (20260917 | Detects win.shifu.)
rule win_shifu_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.shifu."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shifu"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 740a c74618d4d53602 894d18 ff7508 ff7628 ff5624 8b4518 }
            // n = 7, score = 100
            //   740a                 | je                  0xc
            //   c74618d4d53602       | mov                 dword ptr [esi + 0x18], 0x236d5d4
            //   894d18               | mov                 dword ptr [ebp + 0x18], ecx
            //   ff7508               | push                dword ptr [ebp + 8]
            //   ff7628               | push                dword ptr [esi + 0x28]
            //   ff5624               | call                dword ptr [esi + 0x24]
            //   8b4518               | mov                 eax, dword ptr [ebp + 0x18]

        $sequence_1 = { 55 8bec 83ec10 8b423c 53 03c2 56 }
            // n = 7, score = 100
            //   55                   | push                ebp
            //   8bec                 | mov                 ebp, esp
            //   83ec10               | sub                 esp, 0x10
            //   8b423c               | mov                 eax, dword ptr [edx + 0x3c]
            //   53                   | push                ebx
            //   03c2                 | add                 eax, edx
            //   56                   | push                esi

        $sequence_2 = { e8???????? 6a02 68???????? 6a01 53 }
            // n = 5, score = 100
            //   e8????????           |                     
            //   6a02                 | push                2
            //   68????????           |                     
            //   6a01                 | push                1
            //   53                   | push                ebx

        $sequence_3 = { bf00800000 57 53 ff35???????? ffd6 57 53 }
            // n = 7, score = 100
            //   bf00800000           | mov                 edi, 0x8000
            //   57                   | push                edi
            //   53                   | push                ebx
            //   ff35????????         |                     
            //   ffd6                 | call                esi
            //   57                   | push                edi
            //   53                   | push                ebx

        $sequence_4 = { 7437 6a0c 58 e8???????? 8bc4 85c0 7411 }
            // n = 7, score = 100
            //   7437                 | je                  0x39
            //   6a0c                 | push                0xc
            //   58                   | pop                 eax
            //   e8????????           |                     
            //   8bc4                 | mov                 eax, esp
            //   85c0                 | test                eax, eax
            //   7411                 | je                  0x13

        $sequence_5 = { e8???????? 894508 3bc3 740b 57 e8???????? 8b4508 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   894508               | mov                 dword ptr [ebp + 8], eax
            //   3bc3                 | cmp                 eax, ebx
            //   740b                 | je                  0xd
            //   57                   | push                edi
            //   e8????????           |                     
            //   8b4508               | mov                 eax, dword ptr [ebp + 8]

        $sequence_6 = { 57 40 50 6800000080 ff7508 8d4df8 8945e8 }
            // n = 7, score = 100
            //   57                   | push                edi
            //   40                   | inc                 eax
            //   50                   | push                eax
            //   6800000080           | push                0x80000000
            //   ff7508               | push                dword ptr [ebp + 8]
            //   8d4df8               | lea                 ecx, [ebp - 8]
            //   8945e8               | mov                 dword ptr [ebp - 0x18], eax

        $sequence_7 = { c645ff01 eb4a 807dff00 740f 8bf3 e8???????? 85c0 }
            // n = 7, score = 100
            //   c645ff01             | mov                 byte ptr [ebp - 1], 1
            //   eb4a                 | jmp                 0x4c
            //   807dff00             | cmp                 byte ptr [ebp - 1], 0
            //   740f                 | je                  0x11
            //   8bf3                 | mov                 esi, ebx
            //   e8????????           |                     
            //   85c0                 | test                eax, eax

        $sequence_8 = { 8d85f8feffff 57 50 ffd3 83c410 8d85f8feffff 50 }
            // n = 7, score = 100
            //   8d85f8feffff         | lea                 eax, [ebp - 0x108]
            //   57                   | push                edi
            //   50                   | push                eax
            //   ffd3                 | call                ebx
            //   83c410               | add                 esp, 0x10
            //   8d85f8feffff         | lea                 eax, [ebp - 0x108]
            //   50                   | push                eax

        $sequence_9 = { 8d85e4feffff 50 ff15???????? 85c0 7465 6a00 }
            // n = 6, score = 100
            //   8d85e4feffff         | lea                 eax, [ebp - 0x11c]
            //   50                   | push                eax
            //   ff15????????         |                     
            //   85c0                 | test                eax, eax
            //   7465                 | je                  0x67
            //   6a00                 | push                0

    condition:
        7 of them and filesize < 344064
}
[TLP:WHITE] win_shifu_w0   (20170603 | Detects SHIFU Banking Trojan)
rule win_shifu_w0 {
	meta:
		description = "Detects SHIFU Banking Trojan"
		author = "Florian Roth"
		contribution = "Daniel Plohmann"
		reference = "http://goo.gl/52n8WE"
		date = "2015-10-31"
		score = 70
		hash = "0066d1c8053ff8b0c07418c7f8d20e5cd64007bb850944269f611febd0c1afe0"
		hash = "3956d32a870d81be34cafc867769b2a2f55a96360070f1cb3d9addc2918357d5"
		hash = "3fde1b2b50fcb36a695f1e6bc577cd930c2343066d98982cf982393e55bfce0d"
		hash = "457ad4a4d4e675fe09f63873ca3364434dc872dde7d9b64ce7db919eaff47485"
		hash = "51edba913e8b83d1388b1be975957e439015289d51d3d5774d501551f220df6f"
		hash = "6611a2b79a3acf0003b1197aa5bfe488a33db69b663c79c6c5b023e86818d38b"
		hash = "72e239924faebf8209f8e3d093f264f778a55efb56b619f26cea73b1c4feb7a4"
		hash = "7a29cb641b9ac33d1bb405d364bc6e9c7ce3e218a8ff295b75ca0922cf418290"
		hash = "92fe4f9a87c796e993820d1bda8040aced36e316de67c9c0c5fc71aadc41e0f8"
		hash = "93ecb6bd7c76e1b66f8c176418e73e274e2c705986d4ac9ede9d25db4091ab05"
		hash = "a0b7fac69a4eb32953c16597da753b15060f6eba452d150109ff8aabc2c56123"
		hash = "a8b6e798116ce0b268e2c9afac61536b8722e86b958bd2ee95c6ecdec86130c9"
		hash = "d6244c1177b679b3d67f6cec34fe0ae87fba21998d4f5024d8eeaf15ca242503"
		hash = "dcc9c38e695ffd121e793c91ca611a4025a116321443297f710a47ce06afb36d"
		source = "https://github.com/mattulm/sfiles_yara/blob/master/malware/shifu_trojan.yar"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.shifu"
        malpedia_version = "20170603"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
	strings:
		$x1 = "\\Gather\\Dividerail.pdb" ascii

		$s0 = "\\payload\\payload.x86.pdb" ascii
		$s1 = "USER_PRIV_GUEST" fullword wide
		$s2 = "USER_PRIV_ADMIN" fullword wide
		$s3 = "USER_PRIV_USER" fullword wide
		$s4 = "%ws\\%ws" wide
	condition:
		($x1 or 5 of ($s*))
}
Download all Yara Rules