SYMBOLCOMMON_NAMEaka. SYNONYMS
win.unidentified_126 (Back to overview)

Unidentified 126 (GoogleSheets C2)

VTCollection    

According to Malware INFO Research Team, the analyzed fake GlobalProtect MSI contains an unsigned native 64-bit Windows executable that acts as a backdoor with a Myanmar-specific activation guardrail, using a public IP geolocation service to check the target's country before proceeding. The malware is written as a native PE32+ x64 Windows GUI application and features a staged design that contacts a Cloudflare Worker configuration gate to receive Google service-account credentials and a spreadsheet identifier, which are then used to authenticate to Google's OAuth endpoint and establish a Google Sheets-based command and control channel. The sample demonstrates capabilities for reading, writing, and polling specific spreadsheet cells to exchange device identifiers, victim metadata, operator commands, and command output, with a static design for executing Windows shell commands and capturing output through a hidden child process. The C2 channel establishment and polling were observed in runtime evidence, but no actual operator tasking, command execution, or result submission was captured.

References
2026-09-02 ⋅ Malware INFO ⋅ Malware INFO Research Team
Fake GlobalProtect MSI Targets Myanmar Using Cloudflare and Google Sheets as C2
Unidentified 126 (GoogleSheets C2)
Yara Rules
[TLP:WHITE] win_unidentified_126_auto (20260917 | Detects win.unidentified_126.)
rule win_unidentified_126_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.unidentified_126."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.unidentified_126"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { b809000000 e9???????? c745e474727565 488bf7 488bcb e8???????? 3a4435e4 }
            // n = 7, score = 100
            //   b809000000           | lea                 eax, [ebp + 0x120]
            //   e9????????           |                     
            //   c745e474727565       | mov                 ecx, dword ptr [eax + 8]
            //   488bf7               | mov                 eax, 0x5d797470
            //   488bcb               | dec                 eax
            //   e8????????           |                     
            //   3a4435e4             | sub                 ecx, eax

        $sequence_1 = { 488b8c2470010000 488bc1 483bd6 0f8270030000 4903d6 488b49f8 482bc1 }
            // n = 7, score = 100
            //   488b8c2470010000     | test                dl, al
            //   488bc1               | je                  0x243
            //   483bd6               | dec                 eax
            //   0f8270030000         | lea                 ebx, [0x52ec4]
            //   4903d6               | dec                 eax
            //   488b49f8             | mov                 ebx, dword ptr [ebp + 8]
            //   482bc1               | dec                 eax

        $sequence_2 = { 4c8be0 488bcb c70000000000 e8???????? 448bf8 483b5de8 0f84c3000000 }
            // n = 7, score = 100
            //   4c8be0               | cmp                 byte ptr [edi], 2
            //   488bcb               | jne                 0xdfc
            //   c70000000000         | dec                 eax
            //   e8????????           |                     
            //   448bf8               | mov                 edi, dword ptr [edi + 8]
            //   483b5de8             | dec                 eax
            //   0f84c3000000         | mov                 esi, dword ptr [edi + 8]

        $sequence_3 = { 488bd3 488d4c2450 e8???????? 4c897580 488d1546cc0400 4c897588 }
            // n = 6, score = 100
            //   488bd3               | mov                 ecx, ebx
            //   488d4c2450           | dec                 eax
            //   e8????????           |                     
            //   4c897580             | mov                 edx, edi
            //   488d1546cc0400       | dec                 eax
            //   4c897588             | sub                 edi, ebx

        $sequence_4 = { e8???????? e9???????? 83e909 0f856c090000 }
            // n = 4, score = 100
            //   e8????????           |                     
            //   e9????????           |                     
            //   83e909               | cmova               ecx, dword ptr [esp + 0x210]
            //   0f856c090000         | dec                 eax

        $sequence_5 = { 488b02 488bda 488bd0 44386819 74f1 44386b19 7480 }
            // n = 7, score = 100
            //   488b02               | dec                 eax
            //   488bda               | mov                 eax, dword ptr [ecx]
            //   488bd0               | dec                 eax
            //   44386819             | arpl                word ptr [eax + 4], cx
            //   74f1                 | dec                 eax
            //   44386b19             | lea                 eax, [0x4843f]
            //   7480                 | dec                 eax

        $sequence_6 = { 488b4d50 f20f104c2450 4533c9 4889442440 4c8bc3 0f2945c0 488d45c0 }
            // n = 7, score = 100
            //   488b4d50             | dec                 eax
            //   f20f104c2450         | mov                 edx, dword ptr [edx]
            //   4533c9               | jmp                 0x121c
            //   4889442440           | dec                 ecx
            //   4c8bc3               | mov                 edx, esp
            //   0f2945c0             | dec                 eax
            //   488d45c0             | mov                 ecx, dword ptr [ebp + 0x70]

        $sequence_7 = { e8???????? 488b0f 482bc3 488bd3 4c8b01 4d8b4808 4c8bc0 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   488b0f               | call                dword ptr [eax + 8]
            //   482bc3               | inc                 ecx
            //   488bd3               | mov                 eax, 3
            //   4c8b01               | dec                 eax
            //   4d8b4808             | lea                 edx, [0x488a7]
            //   4c8bc0               | ret                 

        $sequence_8 = { 488b15???????? 4c8d05d2380600 4c8905???????? 4885d2 7413 488b02 48634804 }
            // n = 7, score = 100
            //   488b15????????       |                     
            //   4c8d05d2380600       | dec                 eax
            //   4c8905????????       |                     
            //   4885d2               | mov                 eax, dword ptr [ecx]
            //   7413                 | call                dword ptr [eax]
            //   488b02               | dec                 esp
            //   48634804             | lea                 ecx, [ecx + 0x10]

        $sequence_9 = { 4c8bc3 49ffc0 46382407 75f7 488bd7 488d4db8 e8???????? }
            // n = 7, score = 100
            //   4c8bc3               | dec                 esp
            //   49ffc0               | mov                 dword ptr [esp + 0x3f0], esp
            //   46382407             | dec                 esp
            //   75f7                 | mov                 dword ptr [esp + 0x3f8], esp
            //   488bd7               | inc                 ebp
            //   488d4db8             | xor                 eax, eax
            //   e8????????           |                     

    condition:
        7 of them and filesize < 899072
}
Download all Yara Rules