malware_sakula_shellcode
Description
Sakula shellcode - taken from decoded setup.msi but may not be unique enough to identify Sakula
Query · yara
strings:
/*
55 push ebp
89 E5 mov ebp, esp
E8 00 00 00 00 call $+5
58 pop eax
83 C0 06 add eax, 6
C9 leave
C3 retn
*/
// Get EIP technique (may not be unique enough to identify Sakula)
// Note this only appears in memory or decoded files
$opcodes01 = { 55 89 E5 E8 00 00 00 00 58 83 C0 06 C9 C3 }
/*
8B 5E 3C mov ebx, [esi+3Ch] ; Offset to PE header
8B 5C 1E 78 mov ebx, [esi+ebx+78h] ; Length of headers
8B 4C 1E 20 mov ecx, [esi+ebx+20h] ; Number of data directories
53 push ebx
8B 5C 1E 24 mov ebx, [esi+ebx+24h] ; Export table
01 F3 add ebx, esi
*/
// Export parser
$opcodes02 = { 8B 5E 3C 8B 5C 1E 78 8B 4C 1E 20 53 8B 5C 1E 24 01 F3 }
condition:
any of them