Actor(s): Lazarus Group, Silent Chollima
There is no description at this point.
rule win_vsingle_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.vsingle." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.vsingle" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 8945fc 56 57 c6850cffffff00 68ef000000 6a00 8d850dffffff } // n = 7, score = 700 // 8945fc | mov dword ptr [ebp - 4], eax // 56 | push esi // 57 | push edi // c6850cffffff00 | mov byte ptr [ebp - 0xf4], 0 // 68ef000000 | push 0xef // 6a00 | push 0 // 8d850dffffff | lea eax, [ebp - 0xf3] $sequence_1 = { 8955c5 8955c9 668955cd 8855cf c645d000 33c0 } // n = 6, score = 700 // 8955c5 | mov dword ptr [ebp - 0x3b], edx // 8955c9 | mov dword ptr [ebp - 0x37], edx // 668955cd | mov word ptr [ebp - 0x33], dx // 8855cf | mov byte ptr [ebp - 0x31], dl // c645d000 | mov byte ptr [ebp - 0x30], 0 // 33c0 | xor eax, eax $sequence_2 = { 51 ff15???????? 8b5508 52 ff15???????? 83c001 } // n = 6, score = 700 // 51 | push ecx // ff15???????? | // 8b5508 | mov edx, dword ptr [ebp + 8] // 52 | push edx // ff15???????? | // 83c001 | add eax, 1 $sequence_3 = { 33c0 668985d4f6ffff 68fe070000 6a00 } // n = 4, score = 700 // 33c0 | xor eax, eax // 668985d4f6ffff | mov word ptr [ebp - 0x92c], ax // 68fe070000 | push 0x7fe // 6a00 | push 0 $sequence_4 = { 8945fc 64a130000000 8945f8 8b45f8 8b4dfc 33cd e8???????? } // n = 7, score = 700 // 8945fc | mov dword ptr [ebp - 4], eax // 64a130000000 | mov eax, dword ptr fs:[0x30] // 8945f8 | mov dword ptr [ebp - 8], eax // 8b45f8 | mov eax, dword ptr [ebp - 8] // 8b4dfc | mov ecx, dword ptr [ebp - 4] // 33cd | xor ecx, ebp // e8???????? | $sequence_5 = { 51 ff15???????? 898564fdffff 83bd64fdffff00 7428 8b9564fdffff } // n = 6, score = 700 // 51 | push ecx // ff15???????? | // 898564fdffff | mov dword ptr [ebp - 0x29c], eax // 83bd64fdffff00 | cmp dword ptr [ebp - 0x29c], 0 // 7428 | je 0x2a // 8b9564fdffff | mov edx, dword ptr [ebp - 0x29c] $sequence_6 = { 33c0 668985ccb6ffff 6800200000 6a00 8d8dceb6ffff } // n = 5, score = 700 // 33c0 | xor eax, eax // 668985ccb6ffff | mov word ptr [ebp - 0x4934], ax // 6800200000 | push 0x2000 // 6a00 | push 0 // 8d8dceb6ffff | lea ecx, [ebp - 0x4932] $sequence_7 = { 51 ff15???????? 8d94057cfeffff 52 } // n = 4, score = 700 // 51 | push ecx // ff15???????? | // 8d94057cfeffff | lea edx, [ebp + eax - 0x184] // 52 | push edx $sequence_8 = { 81f2feed50fa 81eafe544f3b 81eabaac6ad1 8b042a eb0b 8b142b 5b } // n = 7, score = 100 // 81f2feed50fa | xor edx, 0xfa50edfe // 81eafe544f3b | sub edx, 0x3b4f54fe // 81eabaac6ad1 | sub edx, 0xd16aacba // 8b042a | mov eax, dword ptr [edx + ebp] // eb0b | jmp 0xd // 8b142b | mov edx, dword ptr [ebx + ebp] // 5b | pop ebx $sequence_9 = { 8b042b 5b 53 bb8fbc7c14 81c30cf1050f e9???????? } // n = 6, score = 100 // 8b042b | mov eax, dword ptr [ebx + ebp] // 5b | pop ebx // 53 | push ebx // bb8fbc7c14 | mov ebx, 0x147cbc8f // 81c30cf1050f | add ebx, 0xf05f10c // e9???????? | $sequence_10 = { eb3c 59 eb16 ba334d6d4b 81c279cf504e } // n = 5, score = 100 // eb3c | jmp 0x3e // 59 | pop ecx // eb16 | jmp 0x18 // ba334d6d4b | mov edx, 0x4b6d4d33 // 81c279cf504e | add edx, 0x4e50cf79 $sequence_11 = { 81ebe35ad2f1 81c37daa580d 895c2404 5b e9???????? } // n = 5, score = 100 // 81ebe35ad2f1 | sub ebx, 0xf1d25ae3 // 81c37daa580d | add ebx, 0xd58aa7d // 895c2404 | mov dword ptr [esp + 4], ebx // 5b | pop ebx // e9???????? | $sequence_12 = { 81f1073623a7 81c16ea9e414 e9???????? eb15 81f0f63bb4b4 81f0556c2d03 } // n = 6, score = 100 // 81f1073623a7 | xor ecx, 0xa7233607 // 81c16ea9e414 | add ecx, 0x14e4a96e // e9???????? | // eb15 | jmp 0x17 // 81f0f63bb4b4 | xor eax, 0xb4b43bf6 // 81f0556c2d03 | xor eax, 0x32d6c55 $sequence_13 = { b8e64d1443 81e8dc1e5dbe eb0a bf3d4243d4 e9???????? } // n = 5, score = 100 // b8e64d1443 | mov eax, 0x43144de6 // 81e8dc1e5dbe | sub eax, 0xbe5d1edc // eb0a | jmp 0xc // bf3d4243d4 | mov edi, 0xd443423d // e9???????? | $sequence_14 = { be11c85cd5 81f61f666769 81c6bc95fea7 e9???????? 897c2404 5f } // n = 6, score = 100 // be11c85cd5 | mov esi, 0xd55cc811 // 81f61f666769 | xor esi, 0x6967661f // 81c6bc95fea7 | add esi, 0xa7fe95bc // e9???????? | // 897c2404 | mov dword ptr [esp + 4], edi // 5f | pop edi $sequence_15 = { 8bec 83ec14 50 b8733628ff } // n = 4, score = 100 // 8bec | mov ebp, esp // 83ec14 | sub esp, 0x14 // 50 | push eax // b8733628ff | mov eax, 0xff283673 condition: 7 of them and filesize < 940032 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY