SYMBOLCOMMON_NAMEaka. SYNONYMS
win.pinchduke (Back to overview)

PinchDuke

Actor(s): APT29

VTCollection    

According to F-Secure, the PinchDuke information stealer gathers system configuration information, steals user credentials, and collects user files from the compromised host transferring these via HTTP(S) to a C&C server. F-Secure believes that PinchDuke’s credential stealing functionality is based on the source code of the Pinch credential stealing malware (also known as LdPinch) that was developed in the early 2000s and has later been openly distributed on underground forums.

References
2015-09-01 ⋅ F-Secure ⋅ F-Secure Labs
The Dukes - 7 Years of Russian Cyberespionage
PinchDuke
Yara Rules
[TLP:WHITE] win_pinchduke_auto (20260917 | Detects win.pinchduke.)
rule win_pinchduke_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.pinchduke."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pinchduke"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 0bfe 8b7508 897db8 8b7df4 337df8 895df0 237dfc }
            // n = 7, score = 100
            //   0bfe                 | or                  edi, esi
            //   8b7508               | mov                 esi, dword ptr [ebp + 8]
            //   897db8               | mov                 dword ptr [ebp - 0x48], edi
            //   8b7df4               | mov                 edi, dword ptr [ebp - 0xc]
            //   337df8               | xor                 edi, dword ptr [ebp - 8]
            //   895df0               | mov                 dword ptr [ebp - 0x10], ebx
            //   237dfc               | and                 edi, dword ptr [ebp - 4]

        $sequence_1 = { eb1f 6a08 e8???????? 8bf0 3bf7 59 }
            // n = 6, score = 100
            //   eb1f                 | jmp                 0x21
            //   6a08                 | push                8
            //   e8????????           |                     
            //   8bf0                 | mov                 esi, eax
            //   3bf7                 | cmp                 esi, edi
            //   59                   | pop                 ecx

        $sequence_2 = { 99 6a14 5d f7fd 0fbe06 0fbe9284b24100 03542418 }
            // n = 7, score = 100
            //   99                   | cdq                 
            //   6a14                 | push                0x14
            //   5d                   | pop                 ebp
            //   f7fd                 | idiv                ebp
            //   0fbe06               | movsx               eax, byte ptr [esi]
            //   0fbe9284b24100       | movsx               edx, byte ptr [edx + 0x41b284]
            //   03542418             | add                 edx, dword ptr [esp + 0x18]

        $sequence_3 = { 68???????? e8???????? 8d4d58 e8???????? 53 e8???????? 50 }
            // n = 7, score = 100
            //   68????????           |                     
            //   e8????????           |                     
            //   8d4d58               | lea                 ecx, [ebp + 0x58]
            //   e8????????           |                     
            //   53                   | push                ebx
            //   e8????????           |                     
            //   50                   | push                eax

        $sequence_4 = { 8b7d0c 337df4 d1c1 33fa 03f9 037dfc 894824 }
            // n = 7, score = 100
            //   8b7d0c               | mov                 edi, dword ptr [ebp + 0xc]
            //   337df4               | xor                 edi, dword ptr [ebp - 0xc]
            //   d1c1                 | rol                 ecx, 1
            //   33fa                 | xor                 edi, edx
            //   03f9                 | add                 edi, ecx
            //   037dfc               | add                 edi, dword ptr [ebp - 4]
            //   894824               | mov                 dword ptr [eax + 0x24], ecx

        $sequence_5 = { 50 e8???????? 807dff00 59 8d740601 7593 eb64 }
            // n = 7, score = 100
            //   50                   | push                eax
            //   e8????????           |                     
            //   807dff00             | cmp                 byte ptr [ebp - 1], 0
            //   59                   | pop                 ecx
            //   8d740601             | lea                 esi, [esi + eax + 1]
            //   7593                 | jne                 0xffffff95
            //   eb64                 | jmp                 0x66

        $sequence_6 = { 59 33c9 3bf0 0f94c1 8bc1 5e c9 }
            // n = 7, score = 100
            //   59                   | pop                 ecx
            //   33c9                 | xor                 ecx, ecx
            //   3bf0                 | cmp                 esi, eax
            //   0f94c1               | sete                cl
            //   8bc1                 | mov                 eax, ecx
            //   5e                   | pop                 esi
            //   c9                   | leave               

        $sequence_7 = { 8d85fcfeffff 50 e8???????? 8d85fcfeffff 56 50 e8???????? }
            // n = 7, score = 100
            //   8d85fcfeffff         | lea                 eax, [ebp - 0x104]
            //   50                   | push                eax
            //   e8????????           |                     
            //   8d85fcfeffff         | lea                 eax, [ebp - 0x104]
            //   56                   | push                esi
            //   50                   | push                eax
            //   e8????????           |                     

        $sequence_8 = { e8???????? 56 e8???????? 59 59 ff75f4 ff15???????? }
            // n = 7, score = 100
            //   e8????????           |                     
            //   56                   | push                esi
            //   e8????????           |                     
            //   59                   | pop                 ecx
            //   59                   | pop                 ecx
            //   ff75f4               | push                dword ptr [ebp - 0xc]
            //   ff15????????         |                     

        $sequence_9 = { 235df0 33ce 33482c 0bfb 33480c 8bf2 d1c1 }
            // n = 7, score = 100
            //   235df0               | and                 ebx, dword ptr [ebp - 0x10]
            //   33ce                 | xor                 ecx, esi
            //   33482c               | xor                 ecx, dword ptr [eax + 0x2c]
            //   0bfb                 | or                  edi, ebx
            //   33480c               | xor                 ecx, dword ptr [eax + 0xc]
            //   8bf2                 | mov                 esi, edx
            //   d1c1                 | rol                 ecx, 1

    condition:
        7 of them and filesize < 223680
}
Download all Yara Rules