There is no description at this point.
rule win_maskgramstealer_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.maskgramstealer." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.maskgramstealer" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { 7437 48833d????????00 742d 48833d????????00 } // n = 4, score = 200 // 7437 | dec eax // 48833d????????00 | // 742d | lea eax, [esp + 0x70] // 48833d????????00 | $sequence_1 = { 498d1400 8a02 3c5c 7404 } // n = 4, score = 200 // 498d1400 | mov ecx, dword ptr [esp + 0x68] // 8a02 | call dword ptr [ebx] // 3c5c | dec eax // 7404 | mov eax, dword ptr [ebx] $sequence_2 = { 498d1400 8a02 3c5c 7404 3c2f 7503 48ffc2 } // n = 7, score = 200 // 498d1400 | pop eax // 8a02 | dec eax // 3c5c | lea eax, [esp + 0x80] // 7404 | mov dword ptr [esp + 0x30], esi // 3c2f | push 6 // 7503 | dec eax // 48ffc2 | mov edx, ebp $sequence_3 = { 4531c9 428a0409 468a040a 448d50bf 4180fa19 7703 } // n = 6, score = 200 // 4531c9 | inc ecx // 428a0409 | pop eax // 468a040a | dec eax // 448d50bf | xchg eax, ecx // 4180fa19 | xor eax, eax // 7703 | push 3 $sequence_4 = { 7404 39f0 7204 31c0 } // n = 4, score = 200 // 7404 | pop eax // 39f0 | dec eax // 7204 | lea edx, [esp + 0x30] // 31c0 | push 0x12 $sequence_5 = { 4180fa19 7703 83c020 458d50bf 4180fa19 7704 4183c020 } // n = 7, score = 200 // 4180fa19 | inc ecx // 7703 | pop eax // 83c020 | dec eax // 458d50bf | lea ecx, [0x10105] // 4180fa19 | call esi // 7704 | push 0x13 // 4183c020 | dec eax $sequence_6 = { 31c0 b980000000 803d????????00 f3ab } // n = 4, score = 200 // 31c0 | jle 0xb36 // b980000000 | dec ebp // 803d????????00 | // f3ab | arpl sp, di $sequence_7 = { 4438c0 74ea 4429c0 c3 } // n = 4, score = 200 // 4438c0 | ja 0x151e // 74ea | dec ecx // 4429c0 | mov edx, 0x7e03ff // c3 | add byte ptr [eax], al $sequence_8 = { c3 803900 7405 48ffc1 ebf6 31c0 448a0402 } // n = 7, score = 200 // c3 | dec eax // 803900 | mov dword ptr [esp + 0x20], eax // 7405 | dec eax // 48ffc1 | lea eax, [esp + 0xa8] // ebf6 | mov ecx, ebp // 31c0 | dec eax // 448a0402 | mov edx, eax $sequence_9 = { 48833d????????00 488905???????? 7437 48833d????????00 } // n = 4, score = 200 // 48833d????????00 | // 488905???????? | // 7437 | dec eax // 48833d????????00 | condition: 7 of them and filesize < 353280 }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY