Actor(s): Turla
There is no description at this point.
rule win_turla_silentmoon_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.turla_silentmoon." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.turla_silentmoon" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 8b55ec 4a 8945f8 894de4 3bc2 7e26 8b4520 } // n = 7, score = 300 // 8b55ec | mov edx, dword ptr [ebp - 0x14] // 4a | dec edx // 8945f8 | mov dword ptr [ebp - 8], eax // 894de4 | mov dword ptr [ebp - 0x1c], ecx // 3bc2 | cmp eax, edx // 7e26 | jle 0x28 // 8b4520 | mov eax, dword ptr [ebp + 0x20] $sequence_1 = { 7dd1 8b55f0 8b7df4 b920000000 2b8e5c020000 2b4dd0 d3e7 } // n = 7, score = 300 // 7dd1 | jge 0xffffffd3 // 8b55f0 | mov edx, dword ptr [ebp - 0x10] // 8b7df4 | mov edi, dword ptr [ebp - 0xc] // b920000000 | mov ecx, 0x20 // 2b8e5c020000 | sub ecx, dword ptr [esi + 0x25c] // 2b4dd0 | sub ecx, dword ptr [ebp - 0x30] // d3e7 | shl edi, cl $sequence_2 = { 83ec18 8b4620 8b4e18 8b9668020000 53 8b5e24 } // n = 6, score = 300 // 83ec18 | sub esp, 0x18 // 8b4620 | mov eax, dword ptr [esi + 0x20] // 8b4e18 | mov ecx, dword ptr [esi + 0x18] // 8b9668020000 | mov edx, dword ptr [esi + 0x268] // 53 | push ebx // 8b5e24 | mov ebx, dword ptr [esi + 0x24] $sequence_3 = { 8b442420 83c40c 6a00 6880000000 6a02 6a00 6a03 } // n = 7, score = 300 // 8b442420 | mov eax, dword ptr [esp + 0x20] // 83c40c | add esp, 0xc // 6a00 | push 0 // 6880000000 | push 0x80 // 6a02 | push 2 // 6a00 | push 0 // 6a03 | push 3 $sequence_4 = { 85c0 7406 c70000000000 8db794130000 c787c413000000000000 e8???????? } // n = 6, score = 300 // 85c0 | test eax, eax // 7406 | je 8 // c70000000000 | mov dword ptr [eax], 0 // 8db794130000 | lea esi, [edi + 0x1394] // c787c413000000000000 | mov dword ptr [edi + 0x13c4], 0 // e8???????? | $sequence_5 = { 56 8bf8 8944243c e8???????? 83c408 84c0 0f840b070000 } // n = 7, score = 300 // 56 | push esi // 8bf8 | mov edi, eax // 8944243c | mov dword ptr [esp + 0x3c], eax // e8???????? | // 83c408 | add esp, 8 // 84c0 | test al, al // 0f840b070000 | je 0x711 $sequence_6 = { c745f820000000 8bc8 c1f905 8d148b 8bc8 83e11f be01000000 } // n = 7, score = 300 // c745f820000000 | mov dword ptr [ebp - 8], 0x20 // 8bc8 | mov ecx, eax // c1f905 | sar ecx, 5 // 8d148b | lea edx, [ebx + ecx*4] // 8bc8 | mov ecx, eax // 83e11f | and ecx, 0x1f // be01000000 | mov esi, 1 $sequence_7 = { 33c1 898e60020000 898664020000 83fb01 7e07 c7464c00000000 83be6802000002 } // n = 7, score = 300 // 33c1 | xor eax, ecx // 898e60020000 | mov dword ptr [esi + 0x260], ecx // 898664020000 | mov dword ptr [esi + 0x264], eax // 83fb01 | cmp ebx, 1 // 7e07 | jle 9 // c7464c00000000 | mov dword ptr [esi + 0x4c], 0 // 83be6802000002 | cmp dword ptr [esi + 0x268], 2 $sequence_8 = { 52 6880000000 8d44247c 50 51 ff15???????? } // n = 6, score = 300 // 52 | push edx // 6880000000 | push 0x80 // 8d44247c | lea eax, [esp + 0x7c] // 50 | push eax // 51 | push ecx // ff15???????? | $sequence_9 = { 894de4 8945f4 c745f800000000 85c9 0f8e1c010000 8bc1 0591000000 } // n = 7, score = 300 // 894de4 | mov dword ptr [ebp - 0x1c], ecx // 8945f4 | mov dword ptr [ebp - 0xc], eax // c745f800000000 | mov dword ptr [ebp - 8], 0 // 85c9 | test ecx, ecx // 0f8e1c010000 | jle 0x122 // 8bc1 | mov eax, ecx // 0591000000 | add eax, 0x91 condition: 7 of them and filesize < 204800 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY