SYMBOLCOMMON_NAMEaka. SYNONYMS
win.chrgetpdsi_stealer (Back to overview)

ChrGetPdsi Stealer

VTCollection    

ChrGetPdsi is a basic infostealer written in Golang which is designed to steal browser history and logins, and targets Chrome, Edge, and Firefox. The output is written to a text file named chrgetpdsi.txt. Based on the samples analysed, the malware does not appear to have networking capabilities, and therefore it is likely that it is intended to be used in a post-compromise situation where the attacker already has access to the target system and can retrieve the created output file via other means.ChrGetPdsi has been observed being deployed by the Broomstick malware.

References
2024-06-17 ⋅ Rapid7 ⋅ Rapid7
Malvertising Campaign Leads to Execution of Oyster Backdoor
Broomstick ChrGetPdsi Stealer
2024-01-05 ⋅ IBM ⋅ IBM X-Force Exchange
Tomb Crypter and ChrGetPdsi Stealer Analysis Report (INT00011701)
Broomstick ChrGetPdsi Stealer
Yara Rules
[TLP:WHITE] win_chrgetpdsi_stealer_auto (20260917 | Detects win.chrgetpdsi_stealer.)
rule win_chrgetpdsi_stealer_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.chrgetpdsi_stealer."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.chrgetpdsi_stealer"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 488d1505e12100 4839d0 0f848c010000 488b5b40 4885db 0f8442010000 4c8b6b50 }
            // n = 7, score = 500
            //   488d1505e12100       | dec                 eax
            //   4839d0               | mov                 esi, dword ptr [esp + 0xd8]
            //   0f848c010000         | dec                 esp
            //   488b5b40             | mov                 eax, dword ptr [esp + 0x78]
            //   4885db               | dec                 eax
            //   0f8442010000         | cmp                 edi, edx
            //   4c8b6b50             | jae                 0x484

        $sequence_1 = { 4c89bc24a0000000 4c89ac24b0020000 4c89a42498020000 4c898c24a0020000 44885c2430 488b8c2410030000 4c89c8 }
            // n = 7, score = 500
            //   4c89bc24a0000000     | mov                 dword ptr [eax + 0x18], ecx
            //   4c89ac24b0020000     | jmp                 0x329
            //   4c89a42498020000     | dec                 eax
            //   4c898c24a0020000     | lea                 edi, [eax + 0x18]
            //   44885c2430           | dec                 eax
            //   488b8c2410030000     | mov                 ecx, dword ptr [esp + 0x360]
            //   4c89c8               | dec                 eax

        $sequence_2 = { 85c0 74d9 488b842480000000 4c8b4f18 488d15267c1e00 4c89e1 4c8b00 }
            // n = 7, score = 500
            //   85c0                 | dec                 eax
            //   74d9                 | sub                 esp, -0x80
            //   488b842480000000     | ret                 
            //   4c8b4f18             | mov                 dword ptr [eax + 0x40], 0x72
            //   488d15267c1e00       | dec                 eax
            //   4c89e1               | mov                 edi, ebx
            //   4c8b00               | dec                 eax

        $sequence_3 = { e8???????? 488b942400020000 4885d2 be00000000 480f45f2 4889b42400020000 ba00000000 }
            // n = 7, score = 500
            //   e8????????           |                     
            //   488b942400020000     | mov                 eax, dword ptr [esp + 0x420]
            //   4885d2               | dec                 eax
            //   be00000000           | lea                 ebx, [0x1707c4]
            //   480f45f2             | mov                 ecx, 0xc
            //   4889b42400020000     | dec                 eax
            //   ba00000000           | lea                 edi, [0x144ab7]

        $sequence_4 = { c7000a000000 8b8424b8000000 4c8b6b08 ba01000000 4889f1 c7430c00000000 4c8d05fad12000 }
            // n = 7, score = 500
            //   c7000a000000         | nop                 dword ptr [eax]
            //   8b8424b8000000       | test                byte ptr [eax], al
            //   4c8b6b08             | dec                 eax
            //   ba01000000           | mov                 ebx, dword ptr [esp + 0x38]
            //   4889f1               | dec                 eax
            //   c7430c00000000       | lea                 ecx, [0x27e522]
            //   4c8d05fad12000       | mov                 edi, 5

        $sequence_5 = { 750e 488b8c24a0070000 48894818 eb15 488d7818 488b8c24a0070000 0f1f4000 }
            // n = 7, score = 500
            //   750e                 | dec                 eax
            //   488b8c24a0070000     | mov                 edi, ecx
            //   48894818             | dec                 eax
            //   eb15                 | mov                 esi, dword ptr [esp + 0x2a0]
            //   488d7818             | dec                 ecx
            //   488b8c24a0070000     | mov                 eax, ecx
            //   0f1f4000             | dec                 esp

        $sequence_6 = { 4889742478 488d05b3251e00 e8???????? 48c7400806000000 488d1507121f00 488910 488b9424f8000000 }
            // n = 7, score = 500
            //   4889742478           | mov                 dword ptr [esp + 0x58], edx
            //   488d05b3251e00       | dec                 esp
            //   e8????????           |                     
            //   48c7400806000000     | mov                 dword ptr [esp + 0x60], ebx
            //   488d1507121f00       | dec                 eax
            //   488910               | mov                 eax, dword ptr [esp + 0x48]
            //   488b9424f8000000     | ret                 

        $sequence_7 = { 4c89442428 31c0 4889f3 4889d1 488d3d5c961c00 be01000000 e8???????? }
            // n = 7, score = 500
            //   4c89442428           | lea                 ecx, [eax + 4]
            //   31c0                 | dec                 eax
            //   4889f3               | shl                 ecx, 1
            //   4889d1               | dec                 eax
            //   488d3d5c961c00       | mov                 dword ptr [esp + 0x58], ecx
            //   be01000000           | dec                 eax
            //   e8????????           |                     

        $sequence_8 = { 0f855d110000 80780273 7417 e9???????? 4883fb04 7513 813874727565 }
            // n = 7, score = 500
            //   0f855d110000         | mov                 ebx, dword ptr [esp + 0x40]
            //   80780273             | dec                 eax
            //   7417                 | mov                 eax, dword ptr [esp + 0x50]
            //   e9????????           |                     
            //   4883fb04             | nop                 
            //   7513                 | inc                 ebp
            //   813874727565         | test                al, al

        $sequence_9 = { 488db42488050000 41b801000000 4d89c1 488d0d0c911600 e8???????? 488b8c2408040000 4885c9 }
            // n = 7, score = 500
            //   488db42488050000     | movups              xmmword ptr [esp + 0x118], xmm7
            //   41b801000000         | dec                 eax
            //   4d89c1               | lea                 ecx, [0x12cfe8]
            //   488d0d0c911600       | dec                 eax
            //   e8????????           |                     
            //   488b8c2408040000     | mov                 dword ptr [esp], eax
            //   4885c9               | nop                 dword ptr [eax + eax]

    condition:
        7 of them and filesize < 10027008
}
Download all Yara Rules