Ransomware, which appears to be a rebranding of win.cuba.
rule win_vendetta_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.vendetta." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vendetta" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { b001 5e c9 c20c00 53 33db 83f9ff } // n = 7, score = 100 // b001 | mov al, 1 // 5e | pop esi // c9 | leave // c20c00 | ret 0xc // 53 | push ebx // 33db | xor ebx, ebx // 83f9ff | cmp ecx, -1 $sequence_1 = { 8b34cd00814100 8b4d08 6a5a 2bce 5b } // n = 5, score = 100 // 8b34cd00814100 | mov esi, dword ptr [ecx*8 + 0x418100] // 8b4d08 | mov ecx, dword ptr [ebp + 8] // 6a5a | push 0x5a // 2bce | sub ecx, esi // 5b | pop ebx $sequence_2 = { 56 ff15???????? 8a85dff7ffff 8ad8 8b85e8f7ffff 83f8ff } // n = 6, score = 100 // 56 | push esi // ff15???????? | // 8a85dff7ffff | mov al, byte ptr [ebp - 0x821] // 8ad8 | mov bl, al // 8b85e8f7ffff | mov eax, dword ptr [ebp - 0x818] // 83f8ff | cmp eax, -1 $sequence_3 = { 8d8de8f7ffff 50 e8???????? 84c0 0f843b010000 } // n = 5, score = 100 // 8d8de8f7ffff | lea ecx, [ebp - 0x818] // 50 | push eax // e8???????? | // 84c0 | test al, al // 0f843b010000 | je 0x141 $sequence_4 = { 50 e8???????? 83c408 84c0 0f845d010000 6a00 } // n = 6, score = 100 // 50 | push eax // e8???????? | // 83c408 | add esp, 8 // 84c0 | test al, al // 0f845d010000 | je 0x163 // 6a00 | push 0 $sequence_5 = { 7424 57 8d85f8f7ffff 50 6868010000 68???????? } // n = 6, score = 100 // 7424 | je 0x26 // 57 | push edi // 8d85f8f7ffff | lea eax, [ebp - 0x808] // 50 | push eax // 6868010000 | push 0x168 // 68???????? | $sequence_6 = { 8d8df4fbffff e8???????? 838d0cfcffff10 83a5fcfbffff00 51 8d8df4fbffff e8???????? } // n = 7, score = 100 // 8d8df4fbffff | lea ecx, [ebp - 0x40c] // e8???????? | // 838d0cfcffff10 | or dword ptr [ebp - 0x3f4], 0x10 // 83a5fcfbffff00 | and dword ptr [ebp - 0x404], 0 // 51 | push ecx // 8d8df4fbffff | lea ecx, [ebp - 0x40c] // e8???????? | $sequence_7 = { 8bcb e8???????? 83a500fcffff00 51 8d8df8fbffff } // n = 5, score = 100 // 8bcb | mov ecx, ebx // e8???????? | // 83a500fcffff00 | and dword ptr [ebp - 0x400], 0 // 51 | push ecx // 8d8df8fbffff | lea ecx, [ebp - 0x408] $sequence_8 = { 03b40500ffffff 03b094b04100 8bc3 03b5d8feffff 01b5e8feffff } // n = 5, score = 100 // 03b40500ffffff | add esi, dword ptr [ebp + eax - 0x100] // 03b094b04100 | add esi, dword ptr [eax + 0x41b094] // 8bc3 | mov eax, ebx // 03b5d8feffff | add esi, dword ptr [ebp - 0x128] // 01b5e8feffff | add dword ptr [ebp - 0x118], esi $sequence_9 = { 03b098b04100 8bc7 03b5f0feffff 01b5e4feffff } // n = 4, score = 100 // 03b098b04100 | add esi, dword ptr [eax + 0x41b098] // 8bc7 | mov eax, edi // 03b5f0feffff | add esi, dword ptr [ebp - 0x110] // 01b5e4feffff | add dword ptr [ebp - 0x11c], esi condition: 7 of them and filesize < 296960 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY