Browser information stealer, written in Go.
rule win_hackbrowserdata_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.hackbrowserdata." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hackbrowserdata" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { eb14 4889de 0fb7bbc2000000 6689bbc0000000 4889f7 488b37 488b5e18 } // n = 7, score = 100 // eb14 | mov dword ptr [eax], 0 // 4889de | dec eax // 0fb7bbc2000000 | lea eax, [0x5093a6] // 6689bbc0000000 | dec eax // 4889f7 | mov ecx, dword ptr [esp + 0x48] // 488b37 | dec eax // 488b5e18 | lea edx, [ecx + 8] $sequence_1 = { eb1f 488b15???????? 488b35???????? 31c9 eb16 b801000000 eb06 } // n = 7, score = 100 // eb1f | movups xmmword ptr [esp + 0x210], xmm7 // 488b15???????? | // 488b35???????? | // 31c9 | dec eax // eb16 | mov dword ptr [esp + 0x210], eax // b801000000 | dec eax // eb06 | mov dword ptr [esp + 0xb8], ebx $sequence_2 = { eb08 4989f9 bf00000000 0f1f4000 0f8507010000 48897c2460 90 } // n = 7, score = 100 // eb08 | dec eax // 4989f9 | mov dword ptr [esp + 0x28], eax // bf00000000 | dec eax // 0f1f4000 | mov dword ptr [eax], 0 // 0f8507010000 | dec eax // 48897c2460 | mov dword ptr [esp + 0x18], eax // 90 | mov byte ptr [eax], 0xc5 $sequence_3 = { eb0d 31c0 4883c448 5d c3 ffc3 4c89c6 } // n = 7, score = 100 // eb0d | mov dword ptr [esp + 0x20], eax // 31c0 | dec eax // 4883c448 | lea eax, [0x90964a] // 5d | dec eax // c3 | lea ecx, [0x19e] // ffc3 | dec eax // 4c89c6 | mov dword ptr [eax], ecx $sequence_4 = { eb7d 4889bc2490000000 4889f0 4c89e9 488bbc24c0000000 be03000000 41b801000000 } // n = 7, score = 100 // eb7d | dec eax // 4889bc2490000000 | mov ebx, dword ptr [esp + 0x48] // 4889f0 | nop dword ptr [eax + eax] // 4c89e9 | dec eax // 488bbc24c0000000 | mov ecx, eax // be03000000 | dec eax // 41b801000000 | mov edi, ebx $sequence_5 = { f0440fc15a10 488b10 4c8b5828 4c8b6030 488b7838 488b7040 4c8b4020 } // n = 7, score = 100 // f0440fc15a10 | dec eax // 488b10 | mov ebx, eax // 4c8b5828 | dec eax // 4c8b6030 | lea eax, [0x7b1a47] // 488b7838 | nop // 488b7040 | dec eax // 4c8b4020 | mov ebx, eax $sequence_6 = { eb21 4889d3 0f1f440000 e8???????? 85c0 0f85e8000000 488b5c2448 } // n = 7, score = 100 // eb21 | mov dword ptr [esp + 0x60], ebx // 4889d3 | dec eax // 0f1f440000 | mov dword ptr [esp + 0x6a8], edx // e8???????? | // 85c0 | dec eax // 0f85e8000000 | lea eax, [0x487a57] // 488b5c2448 | dec eax $sequence_7 = { 8b5204 0fbae218 6690 7337 488d5140 488b12 4889d1 } // n = 7, score = 100 // 8b5204 | mov byte ptr [esp + 0x28], dl // 0fbae218 | inc esp // 6690 | movzx esp, byte ptr [esp + 0x66] // 7337 | mov byte ptr [esp + 0x29], cl // 488d5140 | movzx ebx, byte ptr [esp + 0x63] // 488b12 | movzx edi, byte ptr [esp + 0x59] // 4889d1 | movzx eax, byte ptr [esp + 0x6b] $sequence_8 = { ffd2 488d15b764b400 4839d0 756f 8403 440f117c2420 488b4b18 } // n = 7, score = 100 // ffd2 | dec eax // 488d15b764b400 | mov ebp, dword ptr [ebp] // 4839d0 | inc esp // 756f | movups xmmword ptr [esp + 0x5f], xmm7 // 8403 | inc esp // 440f117c2420 | movups xmmword ptr [esp + 0x68], xmm7 // 488b4b18 | inc esp $sequence_9 = { eb68 488b9424e8000000 488b1a 488b8424c0000000 b901000000 0f1f00 e8???????? } // n = 7, score = 100 // eb68 | dec eax // 488b9424e8000000 | mov ecx, eax // 488b1a | dec eax // 488b8424c0000000 | mov edi, ebx // b901000000 | dec eax // 0f1f00 | lea eax, [0x8f2986] // e8???????? | condition: 7 of them and filesize < 42451968 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY