Actor(s): Pirate Panda
There is no description at this point.
rule win_winsloader_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.winsloader." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.winsloader" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 8bf0 56 668985fefbffff 8d8500fcffff } // n = 4, score = 200 // 8bf0 | mov esi, eax // 56 | push esi // 668985fefbffff | mov word ptr [ebp - 0x402], ax // 8d8500fcffff | lea eax, [ebp - 0x400] $sequence_1 = { b8???????? 8d7801 8a10 40 84d2 } // n = 5, score = 200 // b8???????? | // 8d7801 | lea edi, [eax + 1] // 8a10 | mov dl, byte ptr [eax] // 40 | inc eax // 84d2 | test dl, dl $sequence_2 = { 83c40c 6800040000 8d8dfcf7ffff 51 } // n = 4, score = 200 // 83c40c | add esp, 0xc // 6800040000 | push 0x400 // 8d8dfcf7ffff | lea ecx, [ebp - 0x804] // 51 | push ecx $sequence_3 = { 81f901100000 72f0 8bd8 c745fcffffffff 85db 7516 56 } // n = 7, score = 200 // 81f901100000 | cmp ecx, 0x1001 // 72f0 | jb 0xfffffff2 // 8bd8 | mov ebx, eax // c745fcffffffff | mov dword ptr [ebp - 4], 0xffffffff // 85db | test ebx, ebx // 7516 | jne 0x18 // 56 | push esi $sequence_4 = { 2bc2 8d1439 8d44020c 0fb6f9 66898435fefbffff 888c3500fcffff 8d4f01 } // n = 7, score = 200 // 2bc2 | sub eax, edx // 8d1439 | lea edx, [ecx + edi] // 8d44020c | lea eax, [edx + eax + 0xc] // 0fb6f9 | movzx edi, cl // 66898435fefbffff | mov word ptr [ebp + esi - 0x402], ax // 888c3500fcffff | mov byte ptr [ebp + esi - 0x400], cl // 8d4f01 | lea ecx, [edi + 1] $sequence_5 = { e8???????? 8b0d???????? 8b15???????? 6689841dfcfbffff a1???????? 898c1dfefbffff 8b0d???????? } // n = 7, score = 200 // e8???????? | // 8b0d???????? | // 8b15???????? | // 6689841dfcfbffff | mov word ptr [ebp + ebx - 0x404], ax // a1???????? | // 898c1dfefbffff | mov dword ptr [ebp + ebx - 0x402], ecx // 8b0d???????? | $sequence_6 = { 68ff030000 8d95fdfbffff 6a00 52 e8???????? } // n = 5, score = 200 // 68ff030000 | push 0x3ff // 8d95fdfbffff | lea edx, [ebp - 0x403] // 6a00 | push 0 // 52 | push edx // e8???????? | $sequence_7 = { 6a00 56 e8???????? 83c40c 6a00 8d45d8 } // n = 6, score = 200 // 6a00 | push 0 // 56 | push esi // e8???????? | // 83c40c | add esp, 0xc // 6a00 | push 0 // 8d45d8 | lea eax, [ebp - 0x28] $sequence_8 = { 33c0 e9???????? 57 8d45dc 50 } // n = 5, score = 200 // 33c0 | xor eax, eax // e9???????? | // 57 | push edi // 8d45dc | lea eax, [ebp - 0x24] // 50 | push eax $sequence_9 = { 8bcf 50 8d4610 50 e8???????? 8b4dc8 8bd0 } // n = 7, score = 100 // 8bcf | mov ecx, edi // 50 | push eax // 8d4610 | lea eax, [esi + 0x10] // 50 | push eax // e8???????? | // 8b4dc8 | mov ecx, dword ptr [ebp - 0x38] // 8bd0 | mov edx, eax $sequence_10 = { 68???????? e8???????? 83c404 668985e8f3ffff 8b8df8f3ffff 668b95e8f3ffff } // n = 6, score = 100 // 68???????? | // e8???????? | // 83c404 | add esp, 4 // 668985e8f3ffff | mov word ptr [ebp - 0xc18], ax // 8b8df8f3ffff | mov ecx, dword ptr [ebp - 0xc08] // 668b95e8f3ffff | mov dx, word ptr [ebp - 0xc18] $sequence_11 = { 83e03f 6bc830 8b0495c0c00110 f644082801 7421 } // n = 5, score = 100 // 83e03f | and eax, 0x3f // 6bc830 | imul ecx, eax, 0x30 // 8b0495c0c00110 | mov eax, dword ptr [edx*4 + 0x1001c0c0] // f644082801 | test byte ptr [eax + ecx + 0x28], 1 // 7421 | je 0x23 $sequence_12 = { 56 50 0f1145e0 e8???????? 6a10 } // n = 5, score = 100 // 56 | push esi // 50 | push eax // 0f1145e0 | movups xmmword ptr [ebp - 0x20], xmm0 // e8???????? | // 6a10 | push 0x10 $sequence_13 = { 8bfe 83e03f c1ff06 6bd830 8b04bdc0c00110 } // n = 5, score = 100 // 8bfe | mov edi, esi // 83e03f | and eax, 0x3f // c1ff06 | sar edi, 6 // 6bd830 | imul ebx, eax, 0x30 // 8b04bdc0c00110 | mov eax, dword ptr [edi*4 + 0x1001c0c0] $sequence_14 = { 85f6 7479 ff75cc 6a00 56 e8???????? ff75cc } // n = 7, score = 100 // 85f6 | test esi, esi // 7479 | je 0x7b // ff75cc | push dword ptr [ebp - 0x34] // 6a00 | push 0 // 56 | push esi // e8???????? | // ff75cc | push dword ptr [ebp - 0x34] $sequence_15 = { c745e0547c0110 e9???????? c745dc03000000 c745e0607c0110 e9???????? 83e80f 7451 } // n = 7, score = 100 // c745e0547c0110 | mov dword ptr [ebp - 0x20], 0x10017c54 // e9???????? | // c745dc03000000 | mov dword ptr [ebp - 0x24], 3 // c745e0607c0110 | mov dword ptr [ebp - 0x20], 0x10017c60 // e9???????? | // 83e80f | sub eax, 0xf // 7451 | je 0x53 condition: 7 of them and filesize < 270336 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY