SYMBOLCOMMON_NAMEaka. SYNONYMS
win.winnti (Back to overview)

Winnti

aka: BleDoor, JUMPALL, RbDoor, Pasteboy

Actor(s): APT17

VTCollection    

There is no description at this point.

References
2024-03-01HarfangLabHarfangLab CTR
A Comprehensive Analysis of i-SOON’s Commercial Offering
ShadowPad Winnti
2023-01-14YouTube (CODE BLUE)Takahiro Haruyama
[CB22]Tracking the Entire Iceberg - Long-term APT Malware C2 Protocol Emulation and Scanning
ShadowPad Winnti
2022-10-25VMware Threat Analysis UnitTakahiro Haruyama
Tracking the entire iceberg: long-term APT malware C2 protocol emulation and scanning
ShadowPad Winnti
2022-09-26Youtube (Virus Bulletin)Takahiro Haruyama
Tracking the entire iceberg long term APT malware C2 protocol emulation and scanning
ShadowPad Winnti
2022-09-19Virus BulletinTakahiro Haruyama
Tracking the entire iceberg - long-term APT malware C2 protocol emulation and scanning
ShadowPad Winnti
2022-05-12TEAMT5Leon Chang, Silvia Yeh
The Next Gen PlugX/ShadowPad? A Dive into the Emerging China-Nexus Modular Trojan, Pangolin8RAT (slides)
KEYPLUG Cobalt Strike CROSSWALK FunnySwitch PlugX ShadowPad Winnti SLIME29 TianWu
2022-05-04CybereasonAkihiro Tomita, Assaf Dahan, Chen Erlich, Daniel Frank, Fusao Tanida, Niv Yona, Ofir Ozer
Operation CuckooBees: A Winnti Malware Arsenal Deep-Dive
PRIVATELOG Spyder STASHLOG Winnti
2022-05-04CybereasonAkihiro Tomita, Assaf Dahan, Chen Erlich, Daniel Frank, Fusao Tanida, Niv Yona, Ofir Ozer
Operation CuckooBees: Deep-Dive into Stealthy Winnti Techniques
PRIVATELOG Spyder STASHLOG Winnti
2022-05-01BushidoTokenBushidoToken
Gamer Cheater Hacker Spy
Egregor HelloKitty NetfilterRootkit RagnarLocker Winnti
2022-03-31Recorded FutureInsikt Group
China-Linked Group TAG-28 Targets India’s “The Times Group” and UIDAI (Aadhaar) Government Agency With Winnti Malware
Winnti TAG-28
2022-01-17Trend MicroCedric Pernet, Daniel Lunghi, Gloria Chen, Jaromír Hořejší, Joseph Chen, Kenney Lu
Delving Deep: An Analysis of Earth Lusca’s Operations
BIOPASS Cobalt Strike FunnySwitch JuicyPotato ShadowPad Winnti Earth Lusca
2021-11-16vmwareTakahiro Haruyama
Monitoring Winnti 4.0 C2 Servers for Two Years
Winnti
2021-09-28Recorded FutureInsikt Group®
4 Chinese APT Groups Identified Targeting Mail Server of Afghan Telecommunications Firm Roshan
PlugX Winnti
2021-09-21Recorded FutureInsikt Group®
China-Linked Group TAG-28 Targets India’s “The Times Group” and UIDAI (Aadhaar) Government Agency With Winnti Malware
Winnti
2021-09-14McAfeeChristiaan Beek
Operation ‘Harvest’: A Deep Dive into a Long-term Campaign
MimiKatz PlugX Winnti
2021-07-08PTSecurityDenis Kuvshinov
How winnti APT grouping works
Korlia ShadowPad Winnti
2021-07-08YouTube (PT Product Update)Denis Kuvshinov
How winnti APT grouping works
Korlia ShadowPad Winnti
2021-07-08Recorded FutureInsikt Group®
Chinese State-Sponsored Activity Group TAG-22 Targets Nepal, the Philippines, and Taiwan Using Winnti and Other Tooling
ShadowPad Spyder Winnti
2021-06-05PrevailionDanny Adamitis
The Gh0st remain the same
Winnti
2021-04-29NTTThreat Detection NTT Ltd.
The Operations of Winnti group
Cobalt Strike ShadowPad Spyder Winnti Earth Lusca
2021-03-10ESET ResearchMathieu Tartare, Matthieu Faou, Thomas Dupuy
Exchange servers under siege from at least 10 APT groups
Microcin MimiKatz PlugX Winnti APT27 APT41 Calypso Tick ToddyCat Tonto Team Vicious Panda
2021-02-28PWC UKPWC UK
Cyber Threats 2020: A Year in Retrospect
elf.wellmess FlowerPower PowGoop 8.t Dropper Agent.BTZ Agent Tesla Appleseed Ave Maria Bankshot BazarBackdoor BLINDINGCAN Chinoxy Conti Cotx RAT Crimson RAT DUSTMAN Emotet FriedEx FunnyDream Hakbit Mailto Maze METALJACK Nefilim Oblique RAT Pay2Key PlugX QakBot REvil Ryuk StoneDrill StrongPity SUNBURST SUPERNOVA TrickBot TurlaRPC Turla SilentMoon WastedLocker WellMess Winnti ZeroCleare APT10 APT23 APT27 APT31 APT41 BlackTech BRONZE EDGEWOOD Inception Framework MUSTANG PANDA Red Charon Red Nue Sea Turtle Tonto Team
2021-02-23CrowdStrikeCrowdStrike
2021 Global Threat Report
RansomEXX Amadey Anchor Avaddon BazarBackdoor Clop Cobalt Strike Conti Cutwail DanaBot DarkSide DoppelPaymer Dridex Egregor Emotet Hakbit IcedID JSOutProx KerrDown LockBit Mailto Maze MedusaLocker Mespinoza Mount Locker NedDnLoader Nemty Pay2Key PlugX Pushdo PwndLocker PyXie QakBot Quasar RAT RagnarLocker Ragnarok RansomEXX REvil Ryuk Sekhmet ShadowPad SmokeLoader Snake SUNBURST SunCrypt TEARDROP TrickBot WastedLocker Winnti Zloader Evilnum OUTLAW SPIDER RIDDLE SPIDER SOLAR SPIDER VIKING SPIDER
2021-01-20FireEyeAndrew Davis
Emulation of Kernel Mode Rootkits With Speakeasy
Winnti
2020-12-24IronNetAdam Hlavek
China cyber attacks: the current threat landscape
PLEAD TSCookie FlowCloud Lookback PLEAD PlugX Quasar RAT Winnti
2020-11-03Kaspersky LabsGReAT
APT trends report Q3 2020
WellMail EVILNUM Janicab Poet RAT AsyncRAT Ave Maria Cobalt Strike Crimson RAT CROSSWALK Dtrack LODEINFO MoriAgent Okrum PlugX POISONPLUG Rover ShadowPad SoreFang Winnti
2020-10-30YouTube (Kaspersky Tech)Kris McConkey
Around the world in 80 days 4.2bn packets
Cobalt Strike Derusbi HyperBro Poison Ivy ShadowPad Winnti
2020-10-12Malwarebytes LabsHossein Jazi, Jérôme Segura, Malwarebytes Threat Intelligence Team, Roberto Santos
Winnti APT group docks in Sri Lanka for new campaign
DBoxAgent SerialVlogger Winnti
2020-09-22vmwareOmar Elgebaly, Takahiro Haruyama
Detecting Threats in Real-time With Active C2 Information
Agent.BTZ Cobalt Strike Dacls NetWire RC PoshC2 Winnti
2020-09-18SymantecThreat Hunter Team
APT41: Indictments Put Chinese Espionage Group in the Spotlight
CROSSWALK PlugX POISONPLUG ShadowPad Winnti
2020-08-06WiredAndy Greenberg
Chinese Hackers Have Pillaged Taiwan's Semiconductor Industry
Cobalt Strike MimiKatz Winnti Red Charon
2020-08-04BlackHatChung-Kuan Chen, Inndy Lin, Shang-De Jiang
Operation Chimera - APT Operation Targets Semiconductor Vendors
Cobalt Strike MimiKatz Winnti Red Charon
2020-04-20QuoScientQuoIntelligence
WINNTI GROUP: Insights From the Past
Winnti
2020-03-04CrowdStrikeCrowdStrike
2020 CrowdStrike Global Threat Report
MESSAGETAP More_eggs 8.t Dropper Anchor BabyShark BadNews Clop Cobalt Strike CobInt Cobra Carbon System Cutwail DanaBot Dharma DoppelDridex DoppelPaymer Dridex Emotet FlawedAmmyy FriedEx Gandcrab Get2 IcedID ISFB KerrDown LightNeuron LockerGoga Maze MECHANICAL Necurs Nokki Outlook Backdoor Phobos Predator The Thief QakBot REvil RobinHood Ryuk SDBbot Skipper SmokeLoader TerraRecon TerraStealer TerraTV TinyLoader TrickBot Vidar Winnti ANTHROPOID SPIDER APT23 APT31 APT39 APT40 BlackTech BuhTrap Charming Kitten CLOCKWORK SPIDER DOPPEL SPIDER FIN7 Gamaredon Group GOBLIN PANDA MONTY SPIDER MUSTANG PANDA NARWHAL SPIDER NOCTURNAL SPIDER PINCHY SPIDER SALTY SPIDER SCULLY SPIDER SMOKY SPIDER Thrip VENOM SPIDER VICEROY TIGER
2020-03-03GIthub (superkhung)superkhung
GitHub Repository: winnti-sniff
Winnti
2020-03-03PWC UKPWC UK
Cyber Threats 2019:A Year in Retrospect
KevDroid MESSAGETAP magecart AndroMut Cobalt Strike CobInt Crimson RAT DNSpionage Dridex Dtrack Emotet FlawedAmmyy FlawedGrace FriedEx Gandcrab Get2 GlobeImposter Grateful POS ISFB Kazuar LockerGoga Nokki QakBot Ramnit REvil Rifdoor RokRAT Ryuk shadowhammer ShadowPad Shifu Skipper StoneDrill Stuxnet TrickBot Winnti ZeroCleare APT41 MUSTANG PANDA Sea Turtle
2020-02-20Carbon BlackTakahiro Haruyama
Threat Analysis: Active C2 Discovery Using Protocol Emulation Part2 (Winnti 4.0)
Winnti
2020-01-31TagesschauJan Lukas Strozyk
Deutsches Chemieunternehmen gehackt
Winnti
2020-01-31ESET ResearchMathieu Tartare
Winnti Group targeting universities in Hong Kong
ShadowPad Winnti
2020-01-01SecureworksSecureWorks
BRONZE ATLAS
Speculoos Winnti ACEHASH CCleaner Backdoor CHINACHOPPER Empire Downloader HTran MimiKatz PlugX Winnti APT41
2019-10-01CrowdStrikeKarl Scheuerman, Piotr Wojtyla
Don't miss the forest for the trees gleaning hunting value from too much intrusion data
Winnti
2019-09-30LastlineJason Zhang, Stefano Ortolani
HELO Winnti: Attack or Scan?
Winnti
2019-09-23MITREMITRE ATT&CK
APT41
Derusbi MESSAGETAP Winnti ASPXSpy BLACKCOFFEE CHINACHOPPER Cobalt Strike Derusbi Empire Downloader Ghost RAT MimiKatz NjRAT PlugX ShadowPad Winnti ZXShell APT41
2019-09-04CarbonBlackTakahiro Haruyama
CB TAU Threat Intelligence Notification: Winnti Malware 4.0
Winnti
2019-09-04FireEyeFireEye
APT41: Double Dragon APT41, a dual espionage and cyber crime operation
EASYNIGHT Winnti
2019-08-09FireEyeFireEye
Double Dragon APT41, a dual espionage and cyber crime operation
CLASSFON crackshot CROSSWALK GEARSHIFT HIGHNOON HIGHNOON.BIN JUMPALL POISONPLUG Winnti
2019-07-24Bayerischer RundfunkHakan Tanriverdi, Jan Strozyk, Maximilian Zierer, Rebecca Ciesielski, Svea Eckert
Attacking the Heart of the German Industry
Winnti
2019-07-24Github (br-data)Hakan Tanriverdi, Jan Strozyk, Maximilian Zierer, Rebecca Ciesielski, Svea Eckert
Winnti analysis
Winnti
2019-04-22Trend MicroMohamad Mokbel
C/C++ Runtime Library Code Tampering in Supply Chain
shadowhammer ShadowPad Winnti
2018-10-01Macnica NetworksMacnica Networks
Trends in cyber espionage (targeted attacks) targeting Japan | First half of 2018
Anel Cobalt Strike Datper FlawedAmmyy Quasar RAT RedLeaves taidoor Winnti xxmm
2018-05-22Github (TKCERT)thyssenkrupp CERT
Nmap Script to scan for Winnti infections
Winnti
2018-03-05Github (TKCERT)TKCERT
Suricata rules to detect Winnti communication
Winnti
2017-04-19Trend MicroTrendmicro
Of Pigs and Malware: Examining a Possible Member of the Winnti Group
Winnti
2017-03-22Trend MicroCedric Pernet
Winnti Abuses GitHub for C&C Communications
Winnti
2016-03-06Github (TKCERT)thyssenkrupp CERT
Network detector for Winnti malware
Winnti
2015-06-22Kaspersky LabsDmitry Tarakanov
Games are over: Winnti is now targeting pharmaceutical companies
Winnti APT41
2015-04-06NovettaNovetta
WINNTI ANALYSIS
Winnti
2015-01-01RuxconMatt McCormack
WHY ATTACKER TOOLSETS DO WHAT THEY DO
Winnti
2013-04-01Kaspersky LabsGReAT
Winnti - More than just a game
portless Winnti
Yara Rules
[TLP:WHITE] win_winnti_auto (20260504 | Detects win.winnti.)
rule win_winnti_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-05-04"
        version = "1"
        description = "Detects win.winnti."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winnti"
        malpedia_rule_date = "20260422"
        malpedia_hash = "a182e35da64e6d71cb55f125c4d4225196523f14"
        malpedia_version = "20260504"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8d7c2410 33db f3ab 8d44240c }
            // n = 4, score = 200
            //   8d7c2410             | lea                 edi, [esp + 0x10]
            //   33db                 | xor                 ebx, ebx
            //   f3ab                 | rep stosd           dword ptr es:[edi], eax
            //   8d44240c             | lea                 eax, [esp + 0xc]

        $sequence_1 = { 8d442418 8d8c2490000000 50 6800020000 }
            // n = 4, score = 200
            //   8d442418             | lea                 eax, [esp + 0x18]
            //   8d8c2490000000       | lea                 ecx, [esp + 0x90]
            //   50                   | push                eax
            //   6800020000           | push                0x200

        $sequence_2 = { 8954242c 663dffff 0f84cf000000 83fa01 7f07 }
            // n = 5, score = 200
            //   8954242c             | mov                 dword ptr [esp + 0x2c], edx
            //   663dffff             | cmp                 ax, 0xffff
            //   0f84cf000000         | je                  0xd5
            //   83fa01               | cmp                 edx, 1
            //   7f07                 | jg                  9

        $sequence_3 = { 5d 8b4744 6a00 53 }
            // n = 4, score = 200
            //   5d                   | pop                 ebp
            //   8b4744               | mov                 eax, dword ptr [edi + 0x44]
            //   6a00                 | push                0
            //   53                   | push                ebx

        $sequence_4 = { 8b8c2470020000 2bdf 83c304 6a00 53 }
            // n = 5, score = 200
            //   8b8c2470020000       | mov                 ecx, dword ptr [esp + 0x270]
            //   2bdf                 | sub                 ebx, edi
            //   83c304               | add                 ebx, 4
            //   6a00                 | push                0
            //   53                   | push                ebx

        $sequence_5 = { 8bf0 b900010000 33c0 8bfe f3ab 83c404 33ff }
            // n = 7, score = 200
            //   8bf0                 | mov                 esi, eax
            //   b900010000           | mov                 ecx, 0x100
            //   33c0                 | xor                 eax, eax
            //   8bfe                 | mov                 edi, esi
            //   f3ab                 | rep stosd           dword ptr es:[edi], eax
            //   83c404               | add                 esp, 4
            //   33ff                 | xor                 edi, edi

        $sequence_6 = { 2bf9 8d5a08 8bc1 8bf7 8bfb 6a00 }
            // n = 6, score = 200
            //   2bf9                 | sub                 edi, ecx
            //   8d5a08               | lea                 ebx, [edx + 8]
            //   8bc1                 | mov                 eax, ecx
            //   8bf7                 | mov                 esi, edi
            //   8bfb                 | mov                 edi, ebx
            //   6a00                 | push                0

        $sequence_7 = { ff15???????? b908000000 33c0 8d7c2414 8d542434 f3ab }
            // n = 6, score = 200
            //   ff15????????         |                     
            //   b908000000           | mov                 ecx, 8
            //   33c0                 | xor                 eax, eax
            //   8d7c2414             | lea                 edi, [esp + 0x14]
            //   8d542434             | lea                 edx, [esp + 0x34]
            //   f3ab                 | rep stosd           dword ptr es:[edi], eax

        $sequence_8 = { 488bcf e8???????? 85c0 7442 488d15726b0000 }
            // n = 5, score = 100
            //   488bcf               | dec                 eax
            //   e8????????           |                     
            //   85c0                 | arpl                cx, bx
            //   7442                 | dec                 eax
            //   488d15726b0000       | lea                 ebp, [0xa507f]

        $sequence_9 = { 7539 410bc0 488d542458 488d0db3210b00 8905???????? 488d05a61e0100 }
            // n = 6, score = 100
            //   7539                 | mov                 eax, dword ptr [ecx + edi*8 + 0xba200]
            //   410bc0               | mov                 cl, byte ptr [eax + esi + 0x3a]
            //   488d542458           | inc                 ecx
            //   488d0db3210b00       | cmp                 cl, al
            //   8905????????         |                     
            //   488d05a61e0100       | jae                 0x6b

        $sequence_10 = { 48ffc5 488d157cf20000 488bcd e8???????? }
            // n = 4, score = 100
            //   48ffc5               | dec                 eax
            //   488d157cf20000       | mov                 edi, ebx
            //   488bcd               | and                 ebx, 0x1f
            //   e8????????           |                     

        $sequence_11 = { 33d2 8bc1 41f7f2 85d2 7402 2bca }
            // n = 6, score = 100
            //   33d2                 | lea                 ecx, [0x116d]
            //   8bc1                 | jmp                 0x14
            //   41f7f2               | dec                 eax
            //   85d2                 | lea                 ecx, [0x117e]
            //   7402                 | xor                 edx, edx
            //   2bca                 | mov                 eax, ecx

        $sequence_12 = { e8???????? 4883c708 4883ff38 7cc2 488b0e }
            // n = 5, score = 100
            //   e8????????           |                     
            //   4883c708             | mov                 dword ptr [esp + 0x30], eax
            //   4883ff38             | dec                 eax
            //   7cc2                 | lea                 eax, [ebp - 0x31]
            //   488b0e               | inc                 ebp

        $sequence_13 = { 4c8d4597 41b930000000 ba04822200 488bce c744242838000000 4889442420 }
            // n = 6, score = 100
            //   4c8d4597             | mov                 dword ptr [esp + 0x28], 0x28
            //   41b930000000         | mov                 dword ptr [ebp - 1], 0x40
            //   ba04822200           | dec                 eax
            //   488bce               | mov                 dword ptr [esp + 0x20], eax
            //   c744242838000000     | mov                 dword ptr [ebp + 3], 0x28
            //   4889442420           | dec                 eax

        $sequence_14 = { 8bc1 48897c2440 4c897c2448 41f7f0 85d2 7405 }
            // n = 6, score = 100
            //   8bc1                 | mov                 dword ptr [ebp + 7], 0x42000042
            //   48897c2440           | dec                 esp
            //   4c897c2448           | lea                 eax, [ebp - 0x69]
            //   41f7f0               | inc                 ecx
            //   85d2                 | mov                 ecx, 0x30
            //   7405                 | mov                 edx, 0x228204

        $sequence_15 = { 7556 833d????????02 734d 8b8db0030000 0fb7532e 488d8560010000 }
            // n = 6, score = 100
            //   7556                 | dec                 eax
            //   833d????????02       |                     
            //   734d                 | mov                 ecx, esi
            //   8b8db0030000         | mov                 dword ptr [esp + 0x28], 0x38
            //   0fb7532e             | dec                 eax
            //   488d8560010000       | mov                 dword ptr [esp + 0x20], eax

        $sequence_16 = { c744242828000000 c745ff40000000 4889442420 c7450328000000 48c7450742000042 }
            // n = 5, score = 100
            //   c744242828000000     | inc                 ecx
            //   c745ff40000000       | div                 edx
            //   4889442420           | test                edx, edx
            //   c7450328000000       | je                  0xb
            //   48c7450742000042     | sub                 ecx, edx

        $sequence_17 = { 3b0d???????? 7369 4863d9 488d2d7f500a00 488bfb 83e31f 48c1ff05 }
            // n = 7, score = 100
            //   3b0d????????         |                     
            //   7369                 | dec                 eax
            //   4863d9               | add                 ebx, 5
            //   488d2d7f500a00       | dec                 eax
            //   488bfb               | add                 eax, esi
            //   83e31f               | mov                 eax, dword ptr [ebp - 0x4d]
            //   48c1ff05             | inc                 ecx

        $sequence_18 = { 2bc8 750f 488d0d6d110000 ff15???????? eb12 488d0d7e110000 ff15???????? }
            // n = 7, score = 100
            //   2bc8                 | inc                 ecx
            //   750f                 | mov                 eax, ebx
            //   488d0d6d110000       | sub                 ecx, eax
            //   ff15????????         |                     
            //   eb12                 | jne                 0x11
            //   488d0d7e110000       | dec                 eax
            //   ff15????????         |                     

        $sequence_19 = { 7e22 48897b18 48897310 408833 4533c0 488d15cb550100 488bcb }
            // n = 7, score = 100
            //   7e22                 | lea                 esp, [eax - 8]
            //   48897b18             | inc                 esp
            //   48897310             | mov                 byte ptr [eax + esi + 0x39], al
            //   408833               | inc                 ecx
            //   4533c0               | cmp                 ch, 1
            //   488d15cb550100       | jne                 0x34
            //   488bcb               | dec                 ebx

        $sequence_20 = { 8b6c3301 4863c5 4883c305 4803c6 }
            // n = 4, score = 100
            //   8b6c3301             | mov                 eax, ecx
            //   4863c5               | dec                 eax
            //   4883c305             | mov                 dword ptr [esp + 0x40], edi
            //   4803c6               | dec                 esp

        $sequence_21 = { 7402 8913 3bd7 410f92c3 418bc3 }
            // n = 5, score = 100
            //   7402                 | je                  4
            //   8913                 | mov                 dword ptr [ebx], edx
            //   3bd7                 | cmp                 edx, edi
            //   410f92c3             | inc                 ecx
            //   418bc3               | setb                bl

        $sequence_22 = { 448be0 85c0 0f844e010000 488b4c2450 488364242000 488d055d970a00 }
            // n = 6, score = 100
            //   448be0               | mov                 ecx, 0x20
            //   85c0                 | mov                 dword ptr [ebp - 0x2d], eax
            //   0f844e010000         | dec                 eax
            //   488b4c2450           | lea                 eax, [ebp + 0x67]
            //   488364242000         | mov                 edx, 0x22824c
            //   488d055d970a00       | dec                 eax

        $sequence_23 = { 458d60f8 4488443039 4180fd01 752e 4b8b84f900a20b00 8a4c303a 413ac8 }
            // n = 7, score = 100
            //   458d60f8             | mov                 ecx, dword ptr [ebp + 0x3b0]
            //   4488443039           | movzx               edx, word ptr [ebx + 0x2e]
            //   4180fd01             | dec                 eax
            //   752e                 | lea                 eax, [ebp + 0x160]
            //   4b8b84f900a20b00     | mov                 ebp, dword ptr [ebx + esi + 1]
            //   8a4c303a             | dec                 eax
            //   413ac8               | arpl                bp, ax

    condition:
        7 of them and filesize < 1581056
}
[TLP:WHITE] win_winnti_w0   (20190822 | rules used for retrohunting by BR Data.)
rule win_winnti_w0 {
    meta:
        author = "BR Data"
        source = "https://github.com/br-data/2019-winnti-analyse/"
        date = "2019-07-24"
        description = "rules used for retrohunting by BR Data."
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winnti"
        malpedia_version = "20190822"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    strings:
        $load_magic = { C7 44 ?? ?? FF D8 FF E0 }
        $iter = { E9 EA EB EC ED EE EF F0 }
        $jpeg = { FF D8 FF E0 00 00 00 00 00 00 }

    condition:
        uint16(0) == 0x5a4d and
        $jpeg and
        ($load_magic or $iter in (@jpeg[1]..@jpeg[1]+200)) and
        for any i in (1..#jpeg): ( uint8(@jpeg[i] + 11) != 0 )
}
[TLP:WHITE] win_winnti_w1   (20190822 | rules used for retrohunting by BR Data.)
rule win_winnti_w1 {
    meta:
        author = "BR Data"
        source = "https://github.com/br-data/2019-winnti-analyse/"
        date = "2019-07-24"
        description = "rules used for retrohunting by BR Data."
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winnti"
        malpedia_version = "20190822"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
    strings:
        $cooper = "Cooper"
        $pattern = { e9 ea eb ec ed ee ef f0}
    condition:
        uint16(0) == 0x5a4d and $cooper and ($pattern in (@cooper[1]..@cooper[1]+100))
}
[TLP:WHITE] win_winnti_w2   (20191207 | No description)
rule win_winnti_w2 {
    meta:
        author = "Bundesamt fuer Verfassungsschutz"
        source = "https://www.verfassungsschutz.de/download/anlage-2019-12-bfv-cyber-brief-2019-01.txt"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winnti"
        malpedia_version = "20191207"
        malpedia_sharing = "TLP:WHITE"
        malpedia_license = ""
    strings:
        $e1 = "Global\\BFE_Notify_Event_{65a097fe-6102-446a-9f9c-55dfc3f411015}" ascii nocase
        $e2 = "Global\\BFE_Notify_Event_{65a097fe-6102-446a-9f9c-55dfc3f411014}" ascii nocase
        $e3 = "Global\\BFE_Notify_Event_{65a097fe-6102-446a-9f9c-55dfc3f411016}" ascii nocase
        $e4 = "\\BaseNamedObjects\\{B2B87CCA-66BC-4C24-89B2-C23C9EAC2A66}" wide
        $e5 = "BFE_Notify_Event_{7D00FA3C-FBDC-4A8D-AEEB-3F55A4890D2A}" nocase
    condition:
        (any of ($e*))
}
[TLP:WHITE] win_winnti_w3   (20191207 | No description)
rule win_winnti_w3 {
    meta:
        author = "Bundesamt fuer Verfassungsschutz"
        source = "https://www.verfassungsschutz.de/download/anlage-2019-12-bfv-cyber-brief-2019-01.txt"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winnti"
        malpedia_version = "20191207"
        malpedia_sharing = "TLP:WHITE"
        malpedia_license = ""
    strings:
        $a1 = "IPSecMiniPort" wide fullword
        $a2 = "ndis6fw" wide fullword
        $a3 = "TCPIP" wide fullword
        $a4 = "NDIS.SYS" ascii fullword
        $a5 = "ntoskrnl.exe" ascii fullword
        $a6 = "\\BaseNamedObjects\\{B2B87CCA-66BC-4C24-89B2-C23C9EAC2A66}" wide
        $a7 = "\\Device\\Null" wide
        $a8 = "\\Device" wide
        $a9 = "\\Driver" wide
        $b1 = { 66 81 7? ?? 70 17 }
        $b2 = { 81 7? ?? 07 E0 15 00 }
        $b3 = { 8B 46 18 3D 03 60 15 00 }
    condition:
        (6 of ($a*)) and (2 of ($b*))
}
Download all Yara Rules