Shellcode-based malware family that according to ESET Research was likely written by the same authors as win.crosswalk.
rule win_sidewalk_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.sidewalk." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.sidewalk" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { c1e810 880a c1e918 884202 884a03 4183f810 } // n = 6, score = 200 // c1e810 | jne 0xffffffde // 880a | dec eax // c1e918 | arpl word ptr [ebp + 0x7f], ax // 884202 | xor ebx, ebx // 884a03 | inc ecx // 4183f810 | mov byte ptr [eax + ecx], al $sequence_1 = { 0bc8 41890c10 488d5204 4983e901 75d4 4863457f } // n = 6, score = 200 // 0bc8 | or ecx, eax // 41890c10 | inc ecx // 488d5204 | mov dword ptr [eax + edx], ecx // 4983e901 | dec eax // 75d4 | lea edx, [edx + 4] // 4863457f | dec ecx $sequence_2 = { 4489750f 44897d03 448965ff 44896dfb } // n = 4, score = 200 // 4489750f | sub ecx, 1 // 44897d03 | jne 0xffffffd6 // 448965ff | dec eax // 44896dfb | arpl word ptr [ebp + 0x7f], ax $sequence_3 = { 8bc2 33c6 c1c010 4403d8 } // n = 4, score = 200 // 8bc2 | jge 0x17 // 33c6 | mov al, byte ptr [edi + ecx] // c1c010 | xor al, byte ptr [ecx] // 4403d8 | inc ecx $sequence_4 = { 3201 41880408 48ffc1 488d040a } // n = 4, score = 200 // 3201 | dec eax // 41880408 | lea edx, [edx + 4] // 48ffc1 | inc ecx // 488d040a | mov ecx, dword ptr [ecx] $sequence_5 = { c1c010 4403d8 4133db c1c30c 03d3 8bf2 } // n = 6, score = 200 // c1c010 | shl eax, 2 // 4403d8 | dec ebp // 4133db | lea ecx, [ecx + 4] // c1c30c | mov eax, ecx // 03d3 | shr eax, 0x10 // 8bf2 | mov byte ptr [edx], cl $sequence_6 = { c1c708 4403df 458bc3 4433c0 418bc5 } // n = 5, score = 200 // c1c708 | dec esp // 4403df | lea ecx, [ebp - 0x29] // 458bc3 | inc ecx // 4433c0 | mov ecx, dword ptr [ecx] // 418bc5 | inc ecx $sequence_7 = { 418b09 418bc0 c1e002 4d8d4904 } // n = 4, score = 200 // 418b09 | cmp eax, esi // 418bc0 | jl 0xffffffe4 // c1e002 | dec eax // 4d8d4904 | add esi, 0x40 $sequence_8 = { c1c608 c1c010 4403de 4403e8 4133db } // n = 5, score = 200 // c1c608 | jl 0xffffffeb // c1c010 | dec eax // 4403de | add esi, 0x40 // 4403e8 | dec eax // 4133db | add ebx, 0x40 $sequence_9 = { c1c610 4433f2 c1c710 4403df } // n = 4, score = 200 // c1c610 | lea eax, [edx + ecx] // 4433f2 | dec eax // c1c710 | cmp eax, esi // 4403df | jl 0xffffffee $sequence_10 = { c1c710 4403df 41c1c610 4503e6 4403cb 4533d1 4403ee } // n = 7, score = 200 // c1c710 | add esi, 0x40 // 4403df | dec eax // 41c1c610 | inc ecx // 4503e6 | dec eax // 4403cb | lea eax, [edx + ecx] // 4533d1 | dec eax // 4403ee | cmp eax, esi $sequence_11 = { 0fb642fe c1e108 0bc8 41890c10 } // n = 4, score = 200 // 0fb642fe | shl ecx, 8 // c1e108 | or ecx, eax // 0bc8 | inc ecx // 41890c10 | mov dword ptr [eax + edx], ecx $sequence_12 = { 483bc6 7ce2 4883c640 4883c340 } // n = 4, score = 200 // 483bc6 | inc esp // 7ce2 | mov dword ptr [ebp + 0xf], esi // 4883c640 | inc esp // 4883c340 | mov dword ptr [ebp + 3], edi $sequence_13 = { 48ffc1 488d040a 483bc6 7ce2 } // n = 4, score = 200 // 48ffc1 | add esi, 0x40 // 488d040a | or ecx, eax // 483bc6 | inc ecx // 7ce2 | mov dword ptr [eax + edx], ecx $sequence_14 = { 33d0 418bc7 33c3 c1c207 c1c00c 4403c8 4533d1 } // n = 7, score = 200 // 33d0 | dec esp // 418bc7 | lea ecx, [ebp - 0x29] // 33c3 | inc ecx // c1c207 | mov ecx, dword ptr [ecx] // c1c00c | inc ecx // 4403c8 | mov eax, eax // 4533d1 | shl eax, 2 $sequence_15 = { 4403c8 4533d1 41c1c208 4503fa 418bdf 33d8 } // n = 6, score = 200 // 4403c8 | dec eax // 4533d1 | lea eax, [edx + ecx] // 41c1c208 | dec eax // 4503fa | cmp eax, esi // 418bdf | jl 0xffffffeb // 33d8 | dec eax condition: 7 of them and filesize < 237568 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY