SYMBOLCOMMON_NAMEaka. SYNONYMS
win.subzero (Back to overview)

Subzero

aka: Corelump, Jumplump

Actor(s): Denim Tsunami

VTCollection    

There is no description at this point.

References
2022-07-28 ⋅ SOCRadar ⋅ SOCRadar
Threats of Commercialized Malware: Knotweed
Subzero Denim Tsunami
2022-07-27 ⋅ Microsoft ⋅ Microsoft Security Response Center (MSRC), Microsoft Threat Intelligence Center (MSTIC), RiskIQ
Untangling KNOTWEED: European private-sector offensive actor using 0-day exploits
Subzero Denim Tsunami
2021-12-17 ⋅ DSIRF ⋅ DSIRF
DSIRF Company Presentation
Subzero
2021-12-17 ⋅ ⋅ Netzpolitik.org ⋅ Andre Meister
Wir enthüllen den Staatstrojaner „Subzero“ aus Österreich
Subzero
2021-11-19 ⋅ ⋅ FOCUS ⋅ Jan-Philipp Hein
Im Rätsel um gruselige Spionage-Software führt die Spur über Wirecard in den Kreml
Subzero
Yara Rules
[TLP:WHITE] win_subzero_auto (20260917 | Detects win.subzero.)
rule win_subzero_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.subzero."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.subzero"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { e8???????? 498bd4 488bcb 488bc7 ff15???????? 8bd8 85c0 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   498bd4               | lea                 eax, [0x3f089]
            //   488bcb               | dec                 eax
            //   488bc7               | mov                 dword ptr [ebx], eax
            //   ff15????????         |                     
            //   8bd8                 | dec                 eax
            //   85c0                 | mov                 ecx, dword ptr [edi]

        $sequence_1 = { 488b4c2440 488b01 488b4010 ff15???????? 85ff 780c 488b442430 }
            // n = 7, score = 100
            //   488b4c2440           | dec                 eax
            //   488b01               | mov                 ecx, dword ptr [eax]
            //   488b4010             | dec                 eax
            //   ff15????????         |                     
            //   85ff                 | mov                 eax, dword ptr [ecx]
            //   780c                 | xor                 edx, edx
            //   488b442430           | dec                 eax

        $sequence_2 = { 488b02 488b98a8000000 488dbba0000000 488bcf 48ff15???????? 0f1f440000 48897c2430 }
            // n = 7, score = 100
            //   488b02               | add                 edx, ebx
            //   488b98a8000000       | xorps               xmm0, xmm0
            //   488dbba0000000       | movups              xmmword ptr [ebx + 8], xmm0
            //   488bcf               | dec                 eax
            //   48ff15????????       |                     
            //   0f1f440000           | mov                 ecx, dword ptr [esp + 0x30]
            //   48897c2430           | mov                 dword ptr [ebx], 1

        $sequence_3 = { 8bfa 488bd9 c78194000000010000c0 488b4960 33f6 4885c9 7411 }
            // n = 7, score = 100
            //   8bfa                 | dec                 eax
            //   488bd9               | mov                 dword ptr [ebx], ecx
            //   c78194000000010000c0     | dec    eax
            //   488b4960             | test                ecx, ecx
            //   33f6                 | je                  0x300
            //   4885c9               | dec                 eax
            //   7411                 | mov                 eax, dword ptr [ecx]

        $sequence_4 = { 4d8bf4 4d2bf7 49c1fe03 4d85ff 0f8541fc0200 488d04f3 48894710 }
            // n = 7, score = 100
            //   4d8bf4               | dec                 eax
            //   4d2bf7               | mov                 dword ptr [esp + 0x50], eax
            //   49c1fe03             | mov                 eax, dword ptr [esp + 0xf0]
            //   4d85ff               | mov                 dword ptr [esp + 0x48], eax
            //   0f8541fc0200         | mov                 eax, dword ptr [esp + 0xd0]
            //   488d04f3             | mov                 dword ptr [esp + 0x40], eax
            //   48894710             | dec                 eax

        $sequence_5 = { 8bd8 85c0 7833 48832600 4c8d1554ef0300 498bd2 498bca }
            // n = 7, score = 100
            //   8bd8                 | dec                 eax
            //   85c0                 | mov                 ecx, dword ptr [ebx + 0x90]
            //   7833                 | dec                 eax
            //   48832600             | test                ecx, ecx
            //   4c8d1554ef0300       | je                  0x1c36
            //   498bd2               | mov                 edx, dword ptr [ebx + 0x150]
            //   498bca               | dec                 eax

        $sequence_6 = { 488d05b35c0500 488907 4885c9 740d 488b01 488b4008 ff15???????? }
            // n = 7, score = 100
            //   488d05b35c0500       | test                edi, edi
            //   488907               | je                  0x2fb4d
            //   4885c9               | dec                 eax
            //   740d                 | mov                 ecx, dword ptr [esp + 0x80]
            //   488b01               | inc                 ecx
            //   488b4008             | test                ah, 4
            //   ff15????????         |                     

        $sequence_7 = { e8???????? 90 e9???????? 448bcb bad7090000 488b4c2468 4c8d05d7150300 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   90                   | mov                 ebx, eax
            //   e9????????           |                     
            //   448bcb               | test                eax, eax
            //   bad7090000           | js                  0x23b8e
            //   488b4c2468           | dec                 eax
            //   4c8d05d7150300       | lea                 edx, [0x1aa75]

        $sequence_8 = { c6401801 498b4308 488b4808 c6411800 498b4308 488b5008 488b4a10 }
            // n = 7, score = 100
            //   c6401801             | dec                 eax
            //   498b4308             | mov                 ebx, edx
            //   488b4808             | dec                 eax
            //   c6411800             | mov                 edi, ecx
            //   498b4308             | inc                 ecx
            //   488b5008             | movups              xmm6, xmmword ptr [eax]
            //   488b4a10             | dec                 eax

        $sequence_9 = { 498d4be8 498943f0 e8???????? 8bd8 85c0 0f883c6d0300 33c0 }
            // n = 7, score = 100
            //   498d4be8             | dec                 esp
            //   498943f0             | mov                 esi, ecx
            //   e8????????           |                     
            //   8bd8                 | xor                 esi, esi
            //   85c0                 | dec                 eax
            //   0f883c6d0300         | lea                 edx, [ebp - 0x40]
            //   33c0                 | dec                 eax

    condition:
        7 of them and filesize < 1420288
}
Download all Yara Rules