SYMBOLCOMMON_NAMEaka. SYNONYMS
win.grateful_pos (Back to overview)

Grateful POS

aka: FrameworkPOS, SCRAPMINT, trinity

Actor(s): Skeleton Spider, FIN6

VTCollection    

POS malware targets systems that run physical point-of-sale device and operates by inspecting the process memory for data that matches the structure of credit card data (Track1 and Track2 data), such as the account number, expiration date, and other information stored on a card’s magnetic stripe. After the cards are first scanned, the personal account number (PAN) and accompanying data sit in the point-of-sale system’s memory unencrypted while the system determines where to send it for authorization.
Masked as the LogMein software, the GratefulPOS malware appears to have emerged during the fall 2017 shopping season with low detection ratio according to some of the earliest detections displayed on VirusTotal. The first sample was upload in November 2017. Additionally, this malware appears to be related to the Framework POS malware, which was linked to some of the high-profile merchant breaches in the past.

References
2021-01-01 ⋅ Secureworks ⋅ SecureWorks
Threat Profile: GOLD FRANKLIN
Grateful POS Meterpreter MimiKatz RemCom FIN6
2020-03-03 ⋅ PWC UK ⋅ PWC UK
Cyber Threats 2019:A Year in Retrospect
KevDroid MESSAGETAP magecart AndroMut Cobalt Strike CobInt Crimson RAT DNSpionage Dridex Dtrack Emotet FlawedAmmyy FlawedGrace FriedEx Gandcrab Get2 GlobeImposter Grateful POS ISFB Kazuar LockerGoga Nokki QakBot Ramnit REvil Rifdoor RokRAT Ryuk shadowhammer ShadowPad Shifu Skipper StoneDrill Stuxnet TrickBot Winnti ZeroCleare APT41 MUSTANG PANDA Sea Turtle
2020-02-19 ⋅ FireEye ⋅ FireEye
M-Trends 2020
Cobalt Strike Grateful POS LockerGoga QakBot TrickBot
2020-02-13 ⋅ Qianxin ⋅ Qi Anxin Threat Intelligence Center
APT Report 2019
Chrysaor Exodus Dacls VPNFilter DNSRat Griffon KopiLuwak More_eggs SQLRat AppleJeus BONDUPDATER Agent.BTZ Anchor AndroMut AppleJeus BOOSTWRITE Brambul Carbanak Cobalt Strike Dacls DistTrack DNSpionage Dtrack ELECTRICFISH FlawedAmmyy FlawedGrace Get2 Grateful POS HOPLIGHT Imminent Monitor RAT jason Joanap KerrDown KEYMARBLE Lambert LightNeuron LoJax MiniDuke PolyglotDuke PowerRatankba Rising Sun SDBbot ServHelper Snatch Stuxnet TinyMet tRat TrickBot Volgmer X-Agent Zebrocy
2019-12-23 ⋅ Norfolk
POS Malware Used at Fuel Pumps
Grateful POS
2019-12-01 ⋅ VISA ⋅ Visa Security Alert
Cybercrime Groups (FIN8) Targeting Fuel Dispenser Merchants
Grateful POS
2019-05-01 ⋅ Red Canary ⋅ Tony Lambert
FrameworkPOS and the adequate persistent threat
Grateful POS
2017-12-13 ⋅ Vitali Kremez Blog ⋅ Vitali Kremez
Update: Let's Learn: Reversing FIN6 "GratefulPOS" aka "FrameworkPOS" Point-of-Sale Malware in-Depth
Grateful POS
2017-12-08 ⋅ RSA ⋅ Kent Beckman
GratefulPOS credit card stealing malware - just in time for the shopping season
Grateful POS
2016-04-01 ⋅ FireEye ⋅ FireEye
Follow the Money: Dissecting the Operations of the Cyber Crime Group FIN6
Grateful POS FIN6
Yara Rules
[TLP:WHITE] win_grateful_pos_auto (20260917 | Detects win.grateful_pos.)
rule win_grateful_pos_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.grateful_pos."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.grateful_pos"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { b8feffffff eb1a b8fdffffff eb13 }
            // n = 4, score = 600
            //   b8feffffff           | mov                 eax, 0xfffffffe
            //   eb1a                 | jmp                 0x1c
            //   b8fdffffff           | mov                 eax, 0xfffffffd
            //   eb13                 | jmp                 0x15

        $sequence_1 = { 83f801 7510 e8???????? e8???????? }
            // n = 4, score = 600
            //   83f801               | cmp                 eax, 1
            //   7510                 | jne                 0x12
            //   e8????????           |                     
            //   e8????????           |                     

        $sequence_2 = { eb07 b8fcffffff eb02 33c0 }
            // n = 4, score = 600
            //   eb07                 | jmp                 9
            //   b8fcffffff           | mov                 eax, 0xfffffffc
            //   eb02                 | jmp                 4
            //   33c0                 | xor                 eax, eax

        $sequence_3 = { e8???????? 99 b980ee3600 f7f9 }
            // n = 4, score = 600
            //   e8????????           |                     
            //   99                   | cdq                 
            //   b980ee3600           | mov                 ecx, 0x36ee80
            //   f7f9                 | idiv                ecx

        $sequence_4 = { 7407 b8f6ffffff eb02 33c0 }
            // n = 4, score = 600
            //   7407                 | je                  9
            //   b8f6ffffff           | mov                 eax, 0xfffffff6
            //   eb02                 | jmp                 4
            //   33c0                 | xor                 eax, eax

        $sequence_5 = { b8fdffffff eb13 b8fcffffff eb0c }
            // n = 4, score = 600
            //   b8fdffffff           | mov                 eax, 0xfffffffd
            //   eb13                 | jmp                 0x15
            //   b8fcffffff           | mov                 eax, 0xfffffffc
            //   eb0c                 | jmp                 0xe

        $sequence_6 = { 7411 e8???????? e8???????? 33c0 e9???????? }
            // n = 5, score = 600
            //   7411                 | je                  0x13
            //   e8????????           |                     
            //   e8????????           |                     
            //   33c0                 | xor                 eax, eax
            //   e9????????           |                     

        $sequence_7 = { 038ddcfbffff 0fb611 52 68???????? }
            // n = 4, score = 500
            //   038ddcfbffff         | mov                 edx, dword ptr [ebp - 0x698]
            //   0fb611               | add                 edx, 0x3d
            //   52                   | push                edx
            //   68????????           |                     

        $sequence_8 = { 50 8d8d74feffff 51 8b9568f9ffff 83c23d 52 }
            // n = 6, score = 500
            //   50                   | cmp                 dword ptr [ebp - 0x20014], 0x20000
            //   8d8d74feffff         | jbe                 0x1e
            //   51                   | mov                 dword ptr [ebp - 0x2001c], 0x20000
            //   8b9568f9ffff         | jmp                 0x2a
            //   83c23d               | cmp                 dword ptr [ebp - 0x424], 0xf
            //   52                   | jge                 0x67

        $sequence_9 = { c6840de4fbffff2e eb74 8b95d4fbffff 0fb68415e4fbffff 83f830 }
            // n = 5, score = 500
            //   c6840de4fbffff2e     | mov                 byte ptr [ebp + ecx - 0x41c], 0x2e
            //   eb74                 | jmp                 0x76
            //   8b95d4fbffff         | mov                 edx, dword ptr [ebp - 0x42c]
            //   0fb68415e4fbffff     | movzx               eax, byte ptr [ebp + edx - 0x41c]
            //   83f830               | cmp                 eax, 0x30

        $sequence_10 = { 8b4510 50 8d8d74fdffff 51 8b9560f9ffff }
            // n = 5, score = 500
            //   8b4510               | movzx               eax, byte ptr [ebp + edx - 0x20003]
            //   50                   | add                 ecx, dword ptr [ebp - 0x424]
            //   8d8d74fdffff         | movzx               edx, byte ptr [ecx]
            //   51                   | push                edx
            //   8b9560f9ffff         | sub                 ecx, 0xe

        $sequence_11 = { c7421400000000 83bdecfffdff00 0f8404040000 81bdecfffdff00000200 760c c785e4fffdff00000200 eb0c }
            // n = 7, score = 500
            //   c7421400000000       | dec                 eax
            //   83bdecfffdff00       | test                ecx, ecx
            //   0f8404040000         | jne                 0x20
            //   81bdecfffdff00000200     | mov    dword ptr [eax], 0x16
            //   760c                 | jne                 0x10
            //   c785e4fffdff00000200     | xor    ecx, ecx
            //   eb0c                 | dec                 esp

        $sequence_12 = { 7c64 8b85f8fffdff 0fb68c05fbfffdff 83f93a 7d51 8b95f8fffdff 0fb68415fdfffdff }
            // n = 7, score = 500
            //   7c64                 | mov                 edx, dword ptr [ebp - 0x420]
            //   8b85f8fffdff         | sub                 edx, dword ptr [ebp - 0x424]
            //   0fb68c05fbfffdff     | movzx               eax, byte ptr [edx]
            //   83f93a               | cmp                 eax, 0x30
            //   7d51                 | push                eax
            //   8b95f8fffdff         | lea                 ecx, [ebp - 0x18c]
            //   0fb68415fdfffdff     | push                ecx

        $sequence_13 = { 83e90e 51 e8???????? 83c40c 85c0 0f8491000000 6a03 }
            // n = 7, score = 500
            //   83e90e               | jl                  0x66
            //   51                   | mov                 eax, dword ptr [ebp - 0x20008]
            //   e8????????           |                     
            //   83c40c               | movzx               ecx, byte ptr [ebp + eax - 0x20005]
            //   85c0                 | cmp                 ecx, 0x3a
            //   0f8491000000         | jge                 0x5e
            //   6a03                 | mov                 edx, dword ptr [ebp - 0x20008]

        $sequence_14 = { 83bddcfbffff0f 7d5e 8b95e0fbffff 2b95dcfbffff 0fb602 83f830 }
            // n = 6, score = 500
            //   83bddcfbffff0f       | mov                 ecx, dword ptr [esp + 0x58]
            //   7d5e                 | dec                 esp
            //   8b95e0fbffff         | mov                 eax, dword ptr [esp + 0x50]
            //   2b95dcfbffff         | mov                 dword ptr [edx + 0x14], 0
            //   0fb602               | cmp                 dword ptr [ebp - 0x20014], 0
            //   83f830               | je                  0x40a

        $sequence_15 = { 488d051d290200 c3 4883ec28 4885c9 7517 e8???????? c70016000000 }
            // n = 7, score = 200
            //   488d051d290200       | dec                 eax
            //   c3                   | lea                 eax, [0x2291d]
            //   4883ec28             | ret                 
            //   4885c9               | dec                 eax
            //   7517                 | sub                 esp, 0x28
            //   e8????????           |                     
            //   c70016000000         | dec                 eax

    condition:
        7 of them and filesize < 3964928
}
Download all Yara Rules