SYMBOLCOMMON_NAMEaka. SYNONYMS
win.acehash (Back to overview)

ACEHASH

Actor(s): APT41

VTCollection    

ACEHASH is described by FireEye as combined credential harvester that consists of two components, a loader and encrypted/compressed payload. To execute, a password is necessary (e.g. 9839D7F1A0) and the individual modules are addressed with parameters (-m, -w, -h).

References
2020-05-21 ⋅ ESET Research ⋅ Martin Smolár, Mathieu Tartare
No “Game over” for the Winnti Group
ACEHASH HTran MimiKatz PipeMon
2020-01-01 ⋅ Secureworks ⋅ SecureWorks
BRONZE ATLAS
Speculoos Winnti ACEHASH CCleaner Backdoor CHINACHOPPER Empire Downloader HTran MimiKatz PlugX Winnti APT41
2019-11-19 ⋅ FireEye ⋅ Kelli Vanderlee, Nalani Fraser
Achievement Unlocked: Chinese Cyber Espionage Evolves to Support Higher Level Missions
MESSAGETAP TSCookie ACEHASH CHINACHOPPER Cobalt Strike Derusbi Empire Downloader Ghost RAT HIGHNOON HTran MimiKatz NetWire RC POISONPLUG Poison Ivy pupy Quasar RAT ZXShell
2019-08-19 ⋅ FireEye ⋅ Alex Pennino, Matt Bromiley
GAME OVER: Detecting and Stopping an APT41 Operation
ACEHASH CHINACHOPPER HIGHNOON
Yara Rules
[TLP:WHITE] win_acehash_auto (20260917 | Detects win.acehash.)
rule win_acehash_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.acehash."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acehash"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 48894348 884350 48894358 884360 4885ff 7539 488d05b8460300 }
            // n = 7, score = 200
            //   48894348             | mov                 ecx, ecx
            //   884350               | dec                 eax
            //   48894358             | test                edx, edx
            //   884360               | jne                 0xa02
            //   4885ff               | mov                 eax, 0x10
            //   7539                 | dec                 ecx
            //   488d05b8460300       | mov                 edi, eax

        $sequence_1 = { 440bd8 0fb64109 4c8d3da7110300 0bd8 0fb6410a 4c8d0dfa3cffff c1e308 }
            // n = 7, score = 200
            //   440bd8               | ret                 
            //   0fb64109             | dec                 eax
            //   4c8d3da7110300       | test                ebx, ebx
            //   0bd8                 | je                  0x1609
            //   0fb6410a             | dec                 eax
            //   4c8d0dfa3cffff       | mov                 ebx, dword ptr [esp + 0x50]
            //   c1e308               | dec                 eax

        $sequence_2 = { 48d1e8 c0e103 4c33c2 480bc8 410fb6c3 4c03c3 }
            // n = 6, score = 200
            //   48d1e8               | xor                 eax, eax
            //   c0e103               | dec                 eax
            //   4c33c2               | lea                 ecx, [0x32280]
            //   480bc8               | dec                 eax
            //   410fb6c3             | mov                 edx, dword ptr [esp + 0x48]
            //   4c03c3               | xor                 eax, eax

        $sequence_3 = { 33d2 4c8d05d8080300 498bc1 3b08 7411 4883c008 ffc2 }
            // n = 7, score = 200
            //   33d2                 | dec                 eax
            //   4c8d05d8080300       | xor                 ecx, eax
            //   498bc1               | inc                 ebp
            //   3b08                 | mov                 ebx, dword ptr [esi + edx*4 + 0x3c8a0]
            //   7411                 | movzx               eax, byte ptr [ebx + 0xa]
            //   4883c008             | dec                 eax
            //   ffc2                 | xor                 ecx, eax

        $sequence_4 = { 85c0 0f85b5000000 4c8d4587 488d55bf 488d4d87 }
            // n = 5, score = 200
            //   85c0                 | inc                 esp
            //   0f85b5000000         | sub                 eax, dword ptr [esi + ecx*4 + 0x3dda0]
            //   4c8d4587             | mov                 ecx, dword ptr [ebx + 0x54]
            //   488d55bf             | inc                 esp
            //   488d4d87             | add                 eax, dword ptr [esi + eax*4 + 0x3e1a0]

        $sequence_5 = { 488b742420 488b6c2418 418919 488b5c2410 }
            // n = 4, score = 200
            //   488b742420           | dec                 dword ptr [ebp - 0x11]
            //   488b6c2418           | inc                 esp
            //   418919               | mov                 ebx, dword ptr [ebp - 0x19]
            //   488b5c2410           | inc                 esp

        $sequence_6 = { 418bfd 6690 e8???????? 488903 4885c0 0f8404040000 }
            // n = 6, score = 200
            //   418bfd               | lea                 eax, [ebx*4 + 4]
            //   6690                 | dec                 ecx
            //   e8????????           |                     
            //   488903               | mov                 ecx, ecx
            //   4885c0               | dec                 eax
            //   0f8404040000         | mov                 edx, dword ptr [ebx]

        $sequence_7 = { 483305???????? 488bcb 488905???????? ff15???????? 483305???????? 488d152e3b0300 }
            // n = 6, score = 200
            //   483305????????       |                     
            //   488bcb               | inc                 esp
            //   488905????????       |                     
            //   ff15????????         |                     
            //   483305????????       |                     
            //   488d152e3b0300       | mov                 ecx, edx

        $sequence_8 = { 488d0d4a520e00 eb02 33c9 e8???????? 4883c438 c3 4883ec38 }
            // n = 7, score = 200
            //   488d0d4a520e00       | dec                 esp
            //   eb02                 | mov                 ecx, edx
            //   33c9                 | dec                 eax
            //   e8????????           |                     
            //   4883c438             | mov                 ebx, ecx
            //   c3                   | inc                 ebp
            //   4883ec38             | xor                 edx, edx

        $sequence_9 = { 4889bc2420020000 4585d2 745c 4c8d9c24f0000000 6666660f1f840000000000 410fb601 c1e208 }
            // n = 7, score = 200
            //   4889bc2420020000     | dec                 ecx
            //   4585d2               | mov                 edx, edi
            //   745c                 | dec                 esp
            //   4c8d9c24f0000000     | arpl                dx, si
            //   6666660f1f840000000000     | inc    ebp
            //   410fb601             | mov                 ebp, ecx
            //   c1e208               | inc                 ebp

    condition:
        7 of them and filesize < 2318336
}
[TLP:WHITE] win_acehash_w0   (20191207 | No description)
rule win_acehash_w0 {
    meta:
        author = "Bundesamt fuer Verfassungsschutz"
        source = "https://www.verfassungsschutz.de/download/anlage-2019-12-bfv-cyber-brief-2019-01.txt"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.acehash"
        malpedia_version = "20191207"
        malpedia_sharing = "TLP:WHITE"
        malpedia_license = ""
    strings:
        $b1 = { 0F B7 ?? 16 [0-1] (81 E? | 25) 00 20 [0-2] [8] 8B ?? 50 41 B9 40 00 00 00 41 B8 00 10 00 00 }
        $b2 = { 8B 40 28 [5-8] 48 03 C8 48 8B C1 [5-8] 48 89 41 28 }
        $b3 = { 48 6B ?? 28 [5-8] 8B ?? ?? 10 [5-8] 48 6B ?? 28 [5-8] 8B ?? ?? 14 }
        $b4 = { 83 B? 90 00 00 00 00 0F 84 [9-12] 83 B? 94 00 00 00 00 0F 84 }
        $b5 = { (45 | 4D) (31 | 33) C0 BA 01 00 00 00 [10-16] FF 5? 28 [0-1] (84 | 85) C0 }
    condition:
        (4 of ($b*))
}
Download all Yara Rules