SYMBOLCOMMON_NAMEaka. SYNONYMS
win.evilgrab (Back to overview)

EvilGrab

aka: Vidgrab

Actor(s): Stone Panda

VTCollection    

There is no description at this point.

References
2015-08-01 ⋅ Arbor Networks ⋅ ASERT Team
Uncovering the Seven Pointed Dagger
9002 RAT EvilGrab PlugX Trochilus RAT APT9
2015-02-06 ⋅ CrowdStrike ⋅ CrowdStrike
CrowdStrike Global Threat Intel Report 2014
BlackPOS CryptoLocker Derusbi Elise Enfal EvilGrab Gameover P2P HttpBrowser MedusaHTTP Mirage Naikon NetTraveler pirpi PlugX Poison Ivy Sakula RAT Sinowal sykipot taidoor
Yara Rules
[TLP:WHITE] win_evilgrab_auto (20260917 | Detects win.evilgrab.)
rule win_evilgrab_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.evilgrab."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.evilgrab"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8bca 83e103 f3a4 8bb578adffff f68550d0ffff01 7434 bf???????? }
            // n = 7, score = 200
            //   8bca                 | mov                 ecx, edx
            //   83e103               | and                 ecx, 3
            //   f3a4                 | rep movsb           byte ptr es:[edi], byte ptr [esi]
            //   8bb578adffff         | mov                 esi, dword ptr [ebp - 0x5288]
            //   f68550d0ffff01       | test                byte ptr [ebp - 0x2fb0], 1
            //   7434                 | je                  0x36
            //   bf????????           |                     

        $sequence_1 = { 89859cefffff 833f00 0f8e1f020000 8d5f10 8b35???????? }
            // n = 5, score = 200
            //   89859cefffff         | mov                 dword ptr [ebp - 0x1064], eax
            //   833f00               | cmp                 dword ptr [edi], 0
            //   0f8e1f020000         | jle                 0x225
            //   8d5f10               | lea                 ebx, [edi + 0x10]
            //   8b35????????         |                     

        $sequence_2 = { 8b442418 8bfd 8d4c0040 33c0 8bd1 c1e902 }
            // n = 6, score = 200
            //   8b442418             | mov                 eax, dword ptr [esp + 0x18]
            //   8bfd                 | mov                 edi, ebp
            //   8d4c0040             | lea                 ecx, [eax + eax + 0x40]
            //   33c0                 | xor                 eax, eax
            //   8bd1                 | mov                 edx, ecx
            //   c1e902               | shr                 ecx, 2

        $sequence_3 = { 8b7de4 8b4de8 8d4304 3bf0 7375 6a00 }
            // n = 6, score = 200
            //   8b7de4               | mov                 edi, dword ptr [ebp - 0x1c]
            //   8b4de8               | mov                 ecx, dword ptr [ebp - 0x18]
            //   8d4304               | lea                 eax, [ebx + 4]
            //   3bf0                 | cmp                 esi, eax
            //   7375                 | jae                 0x77
            //   6a00                 | push                0

        $sequence_4 = { 83f810 772f 7420 48 7410 48 }
            // n = 6, score = 200
            //   83f810               | cmp                 eax, 0x10
            //   772f                 | ja                  0x31
            //   7420                 | je                  0x22
            //   48                   | dec                 eax
            //   7410                 | je                  0x12
            //   48                   | dec                 eax

        $sequence_5 = { e8???????? 8b5c2414 85c0 7508 53 8bce e8???????? }
            // n = 7, score = 200
            //   e8????????           |                     
            //   8b5c2414             | mov                 ebx, dword ptr [esp + 0x14]
            //   85c0                 | test                eax, eax
            //   7508                 | jne                 0xa
            //   53                   | push                ebx
            //   8bce                 | mov                 ecx, esi
            //   e8????????           |                     

        $sequence_6 = { 6a00 6a00 8d9570f5ffff 52 ff15???????? 6a00 }
            // n = 6, score = 200
            //   6a00                 | push                0
            //   6a00                 | push                0
            //   8d9570f5ffff         | lea                 edx, [ebp - 0xa90]
            //   52                   | push                edx
            //   ff15????????         |                     
            //   6a00                 | push                0

        $sequence_7 = { 57 8d8de8adffff 51 8d95dcadffff 52 8d85e0adffff 50 }
            // n = 7, score = 200
            //   57                   | push                edi
            //   8d8de8adffff         | lea                 ecx, [ebp - 0x5218]
            //   51                   | push                ecx
            //   8d95dcadffff         | lea                 edx, [ebp - 0x5224]
            //   52                   | push                edx
            //   8d85e0adffff         | lea                 eax, [ebp - 0x5220]
            //   50                   | push                eax

        $sequence_8 = { 894e20 51 8b4e1c 6a00 51 8b4e10 52 }
            // n = 7, score = 200
            //   894e20               | mov                 dword ptr [esi + 0x20], ecx
            //   51                   | push                ecx
            //   8b4e1c               | mov                 ecx, dword ptr [esi + 0x1c]
            //   6a00                 | push                0
            //   51                   | push                ecx
            //   8b4e10               | mov                 ecx, dword ptr [esi + 0x10]
            //   52                   | push                edx

        $sequence_9 = { 807b1601 7516 8b4320 83f8ff 7407 50 }
            // n = 6, score = 200
            //   807b1601             | cmp                 byte ptr [ebx + 0x16], 1
            //   7516                 | jne                 0x18
            //   8b4320               | mov                 eax, dword ptr [ebx + 0x20]
            //   83f8ff               | cmp                 eax, -1
            //   7407                 | je                  9
            //   50                   | push                eax

    condition:
        7 of them and filesize < 327680
}
[TLP:WHITE] win_evilgrab_w0   (20170517 | Vidgrab code tricks)
/*
    This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as    long as you use it under this license.

*/

rule win_evilgrab_w0 {
    meta:
        description = "Vidgrab code tricks"
        author = "Seth Hardy"
        last_modified = "2014-06-20"
		source = "https://github.com/mattulm/sfiles_yara/blob/master/malware/Vidgrab.yar"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.evilgrab"
        malpedia_version = "20170517"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
    strings:
        $divbyzero = { B8 02 00 00 00 48 48 BA 02 00 00 00 83 F2 02 F7 F0 }
        // add eax, ecx; xor byte ptr [eax], ??h; inc ecx
        $xorloop = { 03 C1 80 30 (66 | 58) 41 }
        $junk = { 8B 4? ?? 8B 4? ?? 03 45 08 52 5A }
        
    condition:
        all of them
}
[TLP:WHITE] win_evilgrab_w1   (20170517 | Vidgrab Identifying Strings)
/*
    This Yara ruleset is under the GNU-GPLv2 license (http://www.gnu.org/licenses/gpl-2.0.html) and open to any user or organization, as    long as you use it under this license.

*/

rule win_evilgrab_w1 {
    meta:
        description = "Vidgrab Identifying Strings"
        author = "Seth Hardy"
        last_modified = "2014-06-20"
		source = "https://github.com/mattulm/sfiles_yara/blob/master/malware/Vidgrab.yar"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.evilgrab"
        malpedia_version = "20170517"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
    strings:
        $s1 = "IDI_ICON5" wide ascii
        $s2 = "starter.exe"
        $s3 = "wmifw.exe"
        $s4 = "Software\\rar"
        $s5 = "tmp092.tmp"
        $s6 = "temp1.exe"
        
    condition:
       3 of them
}
Download all Yara Rules