SYMBOLCOMMON_NAMEaka. SYNONYMS
win.dexter (Back to overview)

Dexter

aka: LusyPOS
VTCollection    

Dexter is a computer virus or point of sale malware which infects computers running Microsoft Windows and was discovered by IT security firm Seculert, in December 2012. It infects PoS systems worldwide and steals sensitive information such as Credit Card and Debit Card information.

References
2012-12-23 ⋅ Contagio Dump ⋅ Mila Parkour
Dec 2012 Dexter - POS Infostealer samples and information
Dexter
2012-12-21 ⋅ Trend Micro ⋅ Jason Pantig
Infostealer Dexter Targets Checkout Systems
Dexter
2012-12-12 ⋅ Volatility Labs ⋅ Michael Hale Ligh
Unpacking Dexter POS "Memory Dump Parsing" Malware
Dexter
Yara Rules
[TLP:WHITE] win_dexter_auto (20260917 | Detects win.dexter.)
rule win_dexter_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.dexter."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.dexter"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8b0d???????? 51 ff15???????? 6aff 8b15???????? 52 ff15???????? }
            // n = 7, score = 400
            //   8b0d????????         |                     
            //   51                   | push                ecx
            //   ff15????????         |                     
            //   6aff                 | push                -1
            //   8b15????????         |                     
            //   52                   | push                edx
            //   ff15????????         |                     

        $sequence_1 = { 6a01 e8???????? 83c404 68d0070000 ff15???????? ebcf }
            // n = 6, score = 400
            //   6a01                 | push                1
            //   e8????????           |                     
            //   83c404               | add                 esp, 4
            //   68d0070000           | push                0x7d0
            //   ff15????????         |                     
            //   ebcf                 | jmp                 0xffffffd1

        $sequence_2 = { 7508 6a00 ff15???????? ff15???????? a3???????? ff15???????? a3???????? }
            // n = 7, score = 400
            //   7508                 | jne                 0xa
            //   6a00                 | push                0
            //   ff15????????         |                     
            //   ff15????????         |                     
            //   a3????????           |                     
            //   ff15????????         |                     
            //   a3????????           |                     

        $sequence_3 = { a3???????? 833d????????00 750d 6860ea0000 ff15???????? ebd0 c745fc00000000 }
            // n = 7, score = 400
            //   a3????????           |                     
            //   833d????????00       |                     
            //   750d                 | jne                 0xf
            //   6860ea0000           | push                0xea60
            //   ff15????????         |                     
            //   ebd0                 | jmp                 0xffffffd2
            //   c745fc00000000       | mov                 dword ptr [ebp - 4], 0

        $sequence_4 = { 83c40c 68???????? ff15???????? 6a00 6a00 6a00 6a00 }
            // n = 7, score = 400
            //   83c40c               | add                 esp, 0xc
            //   68????????           |                     
            //   ff15????????         |                     
            //   6a00                 | push                0
            //   6a00                 | push                0
            //   6a00                 | push                0
            //   6a00                 | push                0

        $sequence_5 = { ff15???????? e9???????? 6a59 ff15???????? 85c0 7514 }
            // n = 6, score = 400
            //   ff15????????         |                     
            //   e9????????           |                     
            //   6a59                 | push                0x59
            //   ff15????????         |                     
            //   85c0                 | test                eax, eax
            //   7514                 | jne                 0x16

        $sequence_6 = { ff15???????? 6a4a 6a00 68???????? e8???????? 83c40c 6a4a }
            // n = 7, score = 400
            //   ff15????????         |                     
            //   6a4a                 | push                0x4a
            //   6a00                 | push                0
            //   68????????           |                     
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc
            //   6a4a                 | push                0x4a

        $sequence_7 = { 51 e8???????? 83c40c 034508 894508 8b5508 }
            // n = 6, score = 400
            //   51                   | push                ecx
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc
            //   034508               | add                 eax, dword ptr [ebp + 8]
            //   894508               | mov                 dword ptr [ebp + 8], eax
            //   8b5508               | mov                 edx, dword ptr [ebp + 8]

        $sequence_8 = { ff15???????? 85c0 740d 68d0070000 ff15???????? }
            // n = 5, score = 400
            //   ff15????????         |                     
            //   85c0                 | test                eax, eax
            //   740d                 | je                  0xf
            //   68d0070000           | push                0x7d0
            //   ff15????????         |                     

        $sequence_9 = { 51 ff15???????? 85c0 740e 837d0800 7508 6a00 }
            // n = 7, score = 400
            //   51                   | push                ecx
            //   ff15????????         |                     
            //   85c0                 | test                eax, eax
            //   740e                 | je                  0x10
            //   837d0800             | cmp                 dword ptr [ebp + 8], 0
            //   7508                 | jne                 0xa
            //   6a00                 | push                0

    condition:
        7 of them and filesize < 98304
}
Download all Yara Rules