SYMBOLCOMMON_NAMEaka. SYNONYMS
win.tflower (Back to overview)

TFlower

VTCollection    

TFlower is a new ransomware targeting mostly corporate networks discovered in August, 2019. It is reportedly installed on networks by attackers after they gain access via RDP. TFlower displays a console showing activity being performed by the ransomware when it encrypts a machine, further indicating that this ransomware is triggered by the attacker post compromise, similar to Samsam/Samas in terms of TTP. Once encryption is started, the ransomware will conduct a status report to an apparently hard-coded C2. Shadow copies are deleted and the Windows 10 repair environment is disabled by this ransomware. This malware also will terminate any running Outlook.exe process so that the mail files can be encrypted. This ransomware does not add an extention to encrypted files, but prepends the marker "*tflower" and what may be the encrypted encryption key for the file to each affected file. Once encryption is completed, another status report is sent to the C2 server.

References
2021-03-03 ⋅ SYGNIA ⋅ Amitai Ben Shushan, Amnon Kushnir, Boaz Wasserman, Martin Korman, Noam Lifshitz
Lazarus Group’s MATA Framework Leveraged to Deploy TFlower Ransomware
Dacls Dacls Dacls TFlower
2019-09-20 ⋅ Canadian Centre for Cyber Security ⋅ Canadian Centre for Cyber Security
TFlower Ransomware Campaign
TFlower
2019-09-17 ⋅ Bleeping Computer ⋅ Lawrence Abrams
TFlower Ransomware - The Latest Attack Targeting Businesses
TFlower
Yara Rules
[TLP:WHITE] win_tflower_auto (20260917 | Detects win.tflower.)
rule win_tflower_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.tflower."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.tflower"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 42 0fb606 80b838e14f0000 74e9 8a0e }
            // n = 5, score = 200
            //   42                   | inc                 edx
            //   0fb606               | movzx               eax, byte ptr [esi]
            //   80b838e14f0000       | cmp                 byte ptr [eax + 0x4fe138], 0
            //   74e9                 | je                  0xffffffeb
            //   8a0e                 | mov                 cl, byte ptr [esi]

        $sequence_1 = { 000f 7708 0001 7708 }
            // n = 4, score = 200
            //   000f                 | add                 byte ptr [edi], cl
            //   7708                 | ja                  0xa
            //   0001                 | add                 byte ptr [ecx], al
            //   7708                 | ja                  0xa

        $sequence_2 = { 0001 0200 0103 0303 }
            // n = 4, score = 200
            //   0001                 | add                 byte ptr [ecx], al
            //   0200                 | add                 al, byte ptr [eax]
            //   0103                 | add                 dword ptr [ebx], eax
            //   0303                 | add                 eax, dword ptr [ebx]

        $sequence_3 = { 0fb6c9 c1e104 33b1476f4f00 33b9436f4f00 0fb6ca }
            // n = 5, score = 200
            //   0fb6c9               | movzx               ecx, cl
            //   c1e104               | shl                 ecx, 4
            //   33b1476f4f00         | xor                 esi, dword ptr [ecx + 0x4f6f47]
            //   33b9436f4f00         | xor                 edi, dword ptr [ecx + 0x4f6f43]
            //   0fb6ca               | movzx               ecx, dl

        $sequence_4 = { 774c ff2485b05a4700 0fb659ff 49 0fb641ff 49 c1e008 }
            // n = 7, score = 200
            //   774c                 | ja                  0x4e
            //   ff2485b05a4700       | jmp                 dword ptr [eax*4 + 0x475ab0]
            //   0fb659ff             | movzx               ebx, byte ptr [ecx - 1]
            //   49                   | dec                 ecx
            //   0fb641ff             | movzx               eax, byte ptr [ecx - 1]
            //   49                   | dec                 ecx
            //   c1e008               | shl                 eax, 8

        $sequence_5 = { 001a 0c05 003c0c 05004e0c05 }
            // n = 4, score = 200
            //   001a                 | add                 byte ptr [edx], bl
            //   0c05                 | or                  al, 5
            //   003c0c               | add                 byte ptr [esp + ecx], bh
            //   05004e0c05           | add                 eax, 0x50c4e00

        $sequence_6 = { 000b 8605???????? 007885 0500788605 }
            // n = 4, score = 200
            //   000b                 | add                 byte ptr [ebx], cl
            //   8605????????         |                     
            //   007885               | add                 byte ptr [eax - 0x7b], bh
            //   0500788605           | add                 eax, 0x5867800

        $sequence_7 = { 0008 7408 0002 7408 }
            // n = 4, score = 200
            //   0008                 | add                 byte ptr [eax], cl
            //   7408                 | je                  0xa
            //   0002                 | add                 byte ptr [edx], al
            //   7408                 | je                  0xa

        $sequence_8 = { 8d4fff ff248d6cfc4600 4e c1e818 8806 }
            // n = 5, score = 200
            //   8d4fff               | lea                 ecx, [edi - 1]
            //   ff248d6cfc4600       | jmp                 dword ptr [ecx*4 + 0x46fc6c]
            //   4e                   | dec                 esi
            //   c1e818               | shr                 eax, 0x18
            //   8806                 | mov                 byte ptr [esi], al

        $sequence_9 = { 0010 740b 0021 740b }
            // n = 4, score = 200
            //   0010                 | add                 byte ptr [eax], dl
            //   740b                 | je                  0xd
            //   0021                 | add                 byte ptr [ecx], ah
            //   740b                 | je                  0xd

        $sequence_10 = { 8bc3 c1e808 0fb6c0 8b0c8d20ed4e00 330c8520f14e00 8bc6 }
            // n = 6, score = 200
            //   8bc3                 | mov                 eax, ebx
            //   c1e808               | shr                 eax, 8
            //   0fb6c0               | movzx               eax, al
            //   8b0c8d20ed4e00       | mov                 ecx, dword ptr [ecx*4 + 0x4eed20]
            //   330c8520f14e00       | xor                 ecx, dword ptr [eax*4 + 0x4ef120]
            //   8bc6                 | mov                 eax, esi

        $sequence_11 = { 0001 7708 00f3 7608 }
            // n = 4, score = 200
            //   0001                 | add                 byte ptr [ecx], al
            //   7708                 | ja                  0xa
            //   00f3                 | add                 bl, dh
            //   7608                 | jbe                 0xa

        $sequence_12 = { c1e918 0fb6c9 c1e104 3391456f4f00 33b9416f4f00 8b4c244c }
            // n = 6, score = 200
            //   c1e918               | shr                 ecx, 0x18
            //   0fb6c9               | movzx               ecx, cl
            //   c1e104               | shl                 ecx, 4
            //   3391456f4f00         | xor                 edx, dword ptr [ecx + 0x4f6f45]
            //   33b9416f4f00         | xor                 edi, dword ptr [ecx + 0x4f6f41]
            //   8b4c244c             | mov                 ecx, dword ptr [esp + 0x4c]

        $sequence_13 = { 0002 7408 00f7 7308 }
            // n = 4, score = 200
            //   0002                 | add                 byte ptr [edx], al
            //   7408                 | je                  0xa
            //   00f7                 | add                 bh, dh
            //   7308                 | jae                 0xa

        $sequence_14 = { 660f28aac07d4b00 660f54e5 660f58fe 660f58fc }
            // n = 4, score = 200
            //   660f28aac07d4b00     | movapd              xmm5, xmmword ptr [edx + 0x4b7dc0]
            //   660f54e5             | andpd               xmm4, xmm5
            //   660f58fe             | addpd               xmm7, xmm6
            //   660f58fc             | addpd               xmm7, xmm4

        $sequence_15 = { 68???????? ffd6 6a00 6a00 68???????? 68???????? }
            // n = 6, score = 200
            //   68????????           |                     
            //   ffd6                 | call                esi
            //   6a00                 | push                0
            //   6a00                 | push                0
            //   68????????           |                     
            //   68????????           |                     

    condition:
        7 of them and filesize < 6578176
}
Download all Yara Rules