There is no description at this point.
rule win_vanhelsing_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.vanhelsing." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vanhelsing" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 8945bc 744a 50 8b459c 0f57c0 03c7 0f2945c0 } // n = 7, score = 100 // 8945bc | mov dword ptr [ebp - 0x44], eax // 744a | je 0x4c // 50 | push eax // 8b459c | mov eax, dword ptr [ebp - 0x64] // 0f57c0 | xorps xmm0, xmm0 // 03c7 | add eax, edi // 0f2945c0 | movaps xmmword ptr [ebp - 0x40], xmm0 $sequence_1 = { 03d3 8bc2 8995d8fbffff 138d84fbffff 33c6 8bb5f8fbffff 898db0fbffff } // n = 7, score = 100 // 03d3 | add edx, ebx // 8bc2 | mov eax, edx // 8995d8fbffff | mov dword ptr [ebp - 0x428], edx // 138d84fbffff | adc ecx, dword ptr [ebp - 0x47c] // 33c6 | xor eax, esi // 8bb5f8fbffff | mov esi, dword ptr [ebp - 0x408] // 898db0fbffff | mov dword ptr [ebp - 0x450], ecx $sequence_2 = { 897d9c ff7328 e8???????? 8b7320 83c40c } // n = 5, score = 100 // 897d9c | mov dword ptr [ebp - 0x64], edi // ff7328 | push dword ptr [ebx + 0x28] // e8???????? | // 8b7320 | mov esi, dword ptr [ebx + 0x20] // 83c40c | add esp, 0xc $sequence_3 = { 59 59 c3 6a10 68???????? e8???????? 8b7508 } // n = 7, score = 100 // 59 | pop ecx // 59 | pop ecx // c3 | ret // 6a10 | push 0x10 // 68???????? | // e8???????? | // 8b7508 | mov esi, dword ptr [ebp + 8] $sequence_4 = { 898518ffffff 13f7 3385c8feffff 8bce 89b514ffffff 338d0cffffff 8bf0 } // n = 7, score = 100 // 898518ffffff | mov dword ptr [ebp - 0xe8], eax // 13f7 | adc esi, edi // 3385c8feffff | xor eax, dword ptr [ebp - 0x138] // 8bce | mov ecx, esi // 89b514ffffff | mov dword ptr [ebp - 0xec], esi // 338d0cffffff | xor ecx, dword ptr [ebp - 0xf4] // 8bf0 | mov esi, eax $sequence_5 = { 0facc818 c1e208 c1e918 0bd1 899d78f7ffff 8b8df8f7ffff 33db } // n = 7, score = 100 // 0facc818 | shrd eax, ecx, 0x18 // c1e208 | shl edx, 8 // c1e918 | shr ecx, 0x18 // 0bd1 | or edx, ecx // 899d78f7ffff | mov dword ptr [ebp - 0x888], ebx // 8b8df8f7ffff | mov ecx, dword ptr [ebp - 0x808] // 33db | xor ebx, ebx $sequence_6 = { 83c40c 33ff 837b2040 0f82f1000000 b828000000 83c618 2b45b8 } // n = 7, score = 100 // 83c40c | add esp, 0xc // 33ff | xor edi, edi // 837b2040 | cmp dword ptr [ebx + 0x20], 0x40 // 0f82f1000000 | jb 0xf7 // b828000000 | mov eax, 0x28 // 83c618 | add esi, 0x18 // 2b45b8 | sub eax, dword ptr [ebp - 0x48] $sequence_7 = { 8d4db8 2bc1 d1f8 3b4580 7358 807d8600 8a888cd44800 } // n = 7, score = 100 // 8d4db8 | lea ecx, [ebp - 0x48] // 2bc1 | sub eax, ecx // d1f8 | sar eax, 1 // 3b4580 | cmp eax, dword ptr [ebp - 0x80] // 7358 | jae 0x5a // 807d8600 | cmp byte ptr [ebp - 0x7a], 0 // 8a888cd44800 | mov cl, byte ptr [eax + 0x48d48c] $sequence_8 = { 0f29ad00ffffff 0f28eb 0f299d10ffffff 660fd4e8 0f29a540feffff 0f57fc 0f28c5 } // n = 7, score = 100 // 0f29ad00ffffff | movaps xmmword ptr [ebp - 0x100], xmm5 // 0f28eb | movaps xmm5, xmm3 // 0f299d10ffffff | movaps xmmword ptr [ebp - 0xf0], xmm3 // 660fd4e8 | paddq xmm5, xmm0 // 0f29a540feffff | movaps xmmword ptr [ebp - 0x1c0], xmm4 // 0f57fc | xorps xmm7, xmm4 // 0f28c5 | movaps xmm0, xmm5 $sequence_9 = { 898704feffff 0bce 8b8570fbffff f7a5e8fbffff 898f00feffff 8bf8 8bda } // n = 7, score = 100 // 898704feffff | mov dword ptr [edi - 0x1fc], eax // 0bce | or ecx, esi // 8b8570fbffff | mov eax, dword ptr [ebp - 0x490] // f7a5e8fbffff | mul dword ptr [ebp - 0x418] // 898f00feffff | mov dword ptr [edi - 0x200], ecx // 8bf8 | mov edi, eax // 8bda | mov ebx, edx condition: 7 of them and filesize < 2981888 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY