Actor(s): Turla
There is no description at this point.
rule win_turla_rpc_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.turla_rpc." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.turla_rpc" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { c685fe00000055 c785d000000012302113 c785d40000003c393006 c785d80000003c2f3010 } // n = 4, score = 200 // c685fe00000055 | mov byte ptr [ebp + 0xfe], 0x55 // c785d000000012302113 | mov dword ptr [ebp + 0xd0], 0x13213012 // c785d40000003c393006 | mov dword ptr [ebp + 0xd4], 0x630393c // c785d80000003c2f3010 | mov dword ptr [ebp + 0xd8], 0x10302f3c $sequence_1 = { f30f7f85e0010000 660f6f05???????? f30f7f8580010000 660f6f05???????? 66c785ec0000000255 } // n = 5, score = 200 // f30f7f85e0010000 | movdqu xmmword ptr [ebp + 0x1e0], xmm0 // 660f6f05???????? | // f30f7f8580010000 | movdqu xmmword ptr [ebp + 0x180], xmm0 // 660f6f05???????? | // 66c785ec0000000255 | mov word ptr [ebp + 0xec], 0x5502 $sequence_2 = { c7456016273034 c745642130133c c7456839300255 c7851001000016273034 c7851401000021300527 } // n = 5, score = 200 // c7456016273034 | mov dword ptr [ebp + 0x60], 0x34302716 // c745642130133c | mov dword ptr [ebp + 0x64], 0x3c133021 // c7456839300255 | mov dword ptr [ebp + 0x68], 0x55023039 // c7851001000016273034 | mov dword ptr [ebp + 0x110], 0x34302716 // c7851401000021300527 | mov dword ptr [ebp + 0x114], 0x27053021 $sequence_3 = { c7850001000007343c26 c7850401000030102d36 c785080100003025213c 66c7850c0100003a3b } // n = 4, score = 200 // c7850001000007343c26 | mov dword ptr [ebp + 0x100], 0x263c3407 // c7850401000030102d36 | mov dword ptr [ebp + 0x104], 0x362d1030 // c785080100003025213c | mov dword ptr [ebp + 0x108], 0x3c212530 // 66c7850c0100003a3b | mov word ptr [ebp + 0x10c], 0x3b3a $sequence_4 = { c745b834272c14 c645bc55 c7854001000030163930 c78544010000343b2025 c6854801000055 c78560010000013c3830 } // n = 6, score = 200 // c745b834272c14 | mov dword ptr [ebp - 0x48], 0x142c2734 // c645bc55 | mov byte ptr [ebp - 0x44], 0x55 // c7854001000030163930 | mov dword ptr [ebp + 0x140], 0x30391630 // c78544010000343b2025 | mov dword ptr [ebp + 0x144], 0x25203b34 // c6854801000055 | mov byte ptr [ebp + 0x148], 0x55 // c78560010000013c3830 | mov dword ptr [ebp + 0x160], 0x30383c01 $sequence_5 = { c745b06970746f c745b472536163 66c745b86c00 ff15???????? } // n = 4, score = 200 // c745b06970746f | mov dword ptr [ebp - 0x50], 0x6f747069 // c745b472536163 | mov dword ptr [ebp - 0x4c], 0x63615372 // 66c745b86c00 | mov word ptr [ebp - 0x48], 0x6c // ff15???????? | $sequence_6 = { c785f4000000133c2726 c785f800000021133c39 66c785fc0000003002 c685fe00000055 c785d000000012302113 } // n = 5, score = 200 // c785f4000000133c2726 | mov dword ptr [ebp + 0xf4], 0x26273c13 // c785f800000021133c39 | mov dword ptr [ebp + 0xf8], 0x393c1321 // 66c785fc0000003002 | mov word ptr [ebp + 0xfc], 0x230 // c685fe00000055 | mov byte ptr [ebp + 0xfe], 0x55 // c785d000000012302113 | mov dword ptr [ebp + 0xd0], 0x13213012 $sequence_7 = { c6850e01000055 c745c007303431 c745c4133c3930 c645c855 c744244806393030 66c744244c2555 c785c000000006302110 } // n = 7, score = 200 // c6850e01000055 | mov byte ptr [ebp + 0x10e], 0x55 // c745c007303431 | mov dword ptr [ebp - 0x40], 0x31343007 // c745c4133c3930 | mov dword ptr [ebp - 0x3c], 0x30393c13 // c645c855 | mov byte ptr [ebp - 0x38], 0x55 // c744244806393030 | mov dword ptr [esp + 0x48], 0x30303906 // 66c744244c2555 | mov word ptr [esp + 0x4c], 0x5525 // c785c000000006302110 | mov dword ptr [ebp + 0xc0], 0x10213006 $sequence_8 = { c6852e01000055 c745b0193a3431 c745b4193c3727 c745b834272c14 c645bc55 } // n = 5, score = 200 // c6852e01000055 | mov byte ptr [ebp + 0x12e], 0x55 // c745b0193a3431 | mov dword ptr [ebp - 0x50], 0x31343a19 // c745b4193c3727 | mov dword ptr [ebp - 0x4c], 0x27373c19 // c745b834272c14 | mov dword ptr [ebp - 0x48], 0x142c2734 // c645bc55 | mov byte ptr [ebp - 0x44], 0x55 $sequence_9 = { 74ab 8d45c4 50 57 6a00 6a00 ff75c0 } // n = 7, score = 100 // 74ab | je 0xffffffad // 8d45c4 | lea eax, [ebp - 0x3c] // 50 | push eax // 57 | push edi // 6a00 | push 0 // 6a00 | push 0 // ff75c0 | push dword ptr [ebp - 0x40] $sequence_10 = { 8d8548ffffff 50 8d8554ffffff 50 ffb54cffffff ffd6 } // n = 6, score = 100 // 8d8548ffffff | lea eax, [ebp - 0xb8] // 50 | push eax // 8d8554ffffff | lea eax, [ebp - 0xac] // 50 | push eax // ffb54cffffff | push dword ptr [ebp - 0xb4] // ffd6 | call esi $sequence_11 = { 8d4518 c7451840540110 50 8d4dc4 } // n = 4, score = 100 // 8d4518 | lea eax, [ebp + 0x18] // c7451840540110 | mov dword ptr [ebp + 0x18], 0x10015440 // 50 | push eax // 8d4dc4 | lea ecx, [ebp - 0x3c] $sequence_12 = { 7434 8da42400000000 8d047d02000000 50 } // n = 4, score = 100 // 7434 | je 0x36 // 8da42400000000 | lea esp, [esp] // 8d047d02000000 | lea eax, [edi*2 + 2] // 50 | push eax $sequence_13 = { 7527 ff15???????? 83c404 57 ff15???????? ff15???????? 5f } // n = 7, score = 100 // 7527 | jne 0x29 // ff15???????? | // 83c404 | add esp, 4 // 57 | push edi // ff15???????? | // ff15???????? | // 5f | pop edi $sequence_14 = { b802000000 5f 5e 5b 8b8c2480020000 33cc } // n = 6, score = 100 // b802000000 | mov eax, 2 // 5f | pop edi // 5e | pop esi // 5b | pop ebx // 8b8c2480020000 | mov ecx, dword ptr [esp + 0x280] // 33cc | xor ecx, esp $sequence_15 = { c745d453002d00 c745d831002d00 c745dc31003600 c745e02d003000 c745e429000000 c745e861006400 c745ec76006100 } // n = 7, score = 100 // c745d453002d00 | mov dword ptr [ebp - 0x2c], 0x2d0053 // c745d831002d00 | mov dword ptr [ebp - 0x28], 0x2d0031 // c745dc31003600 | mov dword ptr [ebp - 0x24], 0x360031 // c745e02d003000 | mov dword ptr [ebp - 0x20], 0x30002d // c745e429000000 | mov dword ptr [ebp - 0x1c], 0x29 // c745e861006400 | mov dword ptr [ebp - 0x18], 0x640061 // c745ec76006100 | mov dword ptr [ebp - 0x14], 0x610076 condition: 7 of them and filesize < 311296 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY