SYMBOLCOMMON_NAMEaka. SYNONYMS
win.yanluowang (Back to overview)

Yanluowang

aka: Dryxiphia
VTCollection    

According to PCrisk, Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the "README.txt" file containing a ransom note. It appends the ".yanluowang" extension to filenames. Cybercriminals behind Yanluowang are targeting enterprise entities and organizations in the financial sector.

Files encrypted by Yanluowang can be decrypted with this tool (it is possible to decrypt all files if the original file is larger than 3GB. If the original file is smaller than 3GB, then only smaller files can be decrypted).

References
2022-11-22 ⋅ The Record ⋅ Dina Temple-Raston
The Yanluowang ransomware group in their own words
Yanluowang
2022-11-07 ⋅ Darktrace ⋅ Dillon Ashmore, Taisiia Garkava
Inside the Yanluowang Leak: Organization, Members, and Tactics
Yanluowang
2022-10-31 ⋅ Twitter (@CryptoInsane) ⋅ CryptoInsane
Tweet about Yanluowang Leaks
Yanluowang
2022-08-10 ⋅ Cisco ⋅ Nick Biasini
Cisco Talos shares insights related to recent cyber attack on Cisco
Yanluowang UNC2447
2022-04-18 ⋅ Bleeping Computer ⋅ Sergiu Gatlan
Free decryptor released for Yanluowang ransomware victims
Yanluowang
2022-04-18 ⋅ Kaspersky ⋅ AMR
How to recover files encrypted by Yanlouwang
Yanluowang
2022-04-06 ⋅ Github (albertzsigovits) ⋅ Albert Zsigovits
Yanluowang Ransomware Analysis
Yanluowang
2022-03-16 ⋅ Symantec ⋅ Symantec Threat Hunter Team
The Ransomware Threat Landscape: What to Expect in 2022
AvosLocker BlackCat BlackMatter Conti DarkSide DoppelPaymer Emotet Hive Karma Mespinoza Nemty Squirrelwaffle VegaLocker WastedLocker Yanluowang Zeppelin
2021-10-14 ⋅ Symantec ⋅ Threat Hunter Team
New Yanluowang ransomware used in targeted attacks
Yanluowang
Yara Rules
[TLP:WHITE] win_yanluowang_auto (20260917 | Detects win.yanluowang.)
rule win_yanluowang_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.yanluowang."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.yanluowang"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8974241c 8d3437 89742410 8d3528c04500 8b442420 898740010000 c1c008 }
            // n = 7, score = 100
            //   8974241c             | mov                 dword ptr [esp + 0x1c], esi
            //   8d3437               | lea                 esi, [edi + esi]
            //   89742410             | mov                 dword ptr [esp + 0x10], esi
            //   8d3528c04500         | lea                 esi, [0x45c028]
            //   8b442420             | mov                 eax, dword ptr [esp + 0x20]
            //   898740010000         | mov                 dword ptr [edi + 0x140], eax
            //   c1c008               | rol                 eax, 8

        $sequence_1 = { 8d3cc500000000 c1e607 33f9 33f1 33fa 8bd3 335d14 }
            // n = 7, score = 100
            //   8d3cc500000000       | lea                 edi, [eax*8]
            //   c1e607               | shl                 esi, 7
            //   33f9                 | xor                 edi, ecx
            //   33f1                 | xor                 esi, ecx
            //   33fa                 | xor                 edi, edx
            //   8bd3                 | mov                 edx, ebx
            //   335d14               | xor                 ebx, dword ptr [ebp + 0x14]

        $sequence_2 = { c1e103 81f900100000 0f8219010000 8b76fc 83c123 2bc6 83c0fc }
            // n = 7, score = 100
            //   c1e103               | shl                 ecx, 3
            //   81f900100000         | cmp                 ecx, 0x1000
            //   0f8219010000         | jb                  0x11f
            //   8b76fc               | mov                 esi, dword ptr [esi - 4]
            //   83c123               | add                 ecx, 0x23
            //   2bc6                 | sub                 eax, esi
            //   83c0fc               | add                 eax, -4

        $sequence_3 = { 3355e8 8d4808 85c9 7402 8911 3375c0 8d480c }
            // n = 7, score = 100
            //   3355e8               | xor                 edx, dword ptr [ebp - 0x18]
            //   8d4808               | lea                 ecx, [eax + 8]
            //   85c9                 | test                ecx, ecx
            //   7402                 | je                  4
            //   8911                 | mov                 dword ptr [ecx], edx
            //   3375c0               | xor                 esi, dword ptr [ebp - 0x40]
            //   8d480c               | lea                 ecx, [eax + 0xc]

        $sequence_4 = { c745fc00000000 6800040000 c745ec00000000 e8???????? 83c404 8985e0fcffff 85c0 }
            // n = 7, score = 100
            //   c745fc00000000       | mov                 dword ptr [ebp - 4], 0
            //   6800040000           | push                0x400
            //   c745ec00000000       | mov                 dword ptr [ebp - 0x14], 0
            //   e8????????           |                     
            //   83c404               | add                 esp, 4
            //   8985e0fcffff         | mov                 dword ptr [ebp - 0x320], eax
            //   85c0                 | test                eax, eax

        $sequence_5 = { 8d45f0 8d4df8 50 3916 7410 c745f034a44400 c745f409000000 }
            // n = 7, score = 100
            //   8d45f0               | lea                 eax, [ebp - 0x10]
            //   8d4df8               | lea                 ecx, [ebp - 8]
            //   50                   | push                eax
            //   3916                 | cmp                 dword ptr [esi], edx
            //   7410                 | je                  0x12
            //   c745f034a44400       | mov                 dword ptr [ebp - 0x10], 0x44a434
            //   c745f409000000       | mov                 dword ptr [ebp - 0xc], 9

        $sequence_6 = { 7524 8d85c8f5ffff 84db 7407 }
            // n = 4, score = 100
            //   7524                 | jne                 0x26
            //   8d85c8f5ffff         | lea                 eax, [ebp - 0xa38]
            //   84db                 | test                bl, bl
            //   7407                 | je                  9

        $sequence_7 = { 770f 0fbec1 0fb680a0a84400 83e00f eb02 33c0 6bc809 }
            // n = 7, score = 100
            //   770f                 | ja                  0x11
            //   0fbec1               | movsx               eax, cl
            //   0fb680a0a84400       | movzx               eax, byte ptr [eax + 0x44a8a0]
            //   83e00f               | and                 eax, 0xf
            //   eb02                 | jmp                 4
            //   33c0                 | xor                 eax, eax
            //   6bc809               | imul                ecx, eax, 9

        $sequence_8 = { 8bd7 c1fa06 8bc7 83e03f 6bc830 8b049538034600 f644082801 }
            // n = 7, score = 100
            //   8bd7                 | mov                 edx, edi
            //   c1fa06               | sar                 edx, 6
            //   8bc7                 | mov                 eax, edi
            //   83e03f               | and                 eax, 0x3f
            //   6bc830               | imul                ecx, eax, 0x30
            //   8b049538034600       | mov                 eax, dword ptr [edx*4 + 0x460338]
            //   f644082801           | test                byte ptr [eax + ecx + 0x28], 1

        $sequence_9 = { ffb544ecffff 51 8d8df8edffff e8???????? 46 3bb550ecffff 0f8239ffffff }
            // n = 7, score = 100
            //   ffb544ecffff         | push                dword ptr [ebp - 0x13bc]
            //   51                   | push                ecx
            //   8d8df8edffff         | lea                 ecx, [ebp - 0x1208]
            //   e8????????           |                     
            //   46                   | inc                 esi
            //   3bb550ecffff         | cmp                 esi, dword ptr [ebp - 0x13b0]
            //   0f8239ffffff         | jb                  0xffffff3f

    condition:
        7 of them and filesize < 834560
}
Download all Yara Rules