SYMBOLCOMMON_NAMEaka. SYNONYMS
win.snowflake_stealer (Back to overview)

SnowFlake Stealer

VTCollection    

Information stealer, written in Rust.

References
2022-02-14 ⋅ Github (Finch4) ⋅ Finch
SnowFlake Stealer
SnowFlake Stealer
Yara Rules
[TLP:WHITE] win_snowflake_stealer_auto (20260917 | Detects win.snowflake_stealer.)
rule win_snowflake_stealer_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.snowflake_stealer."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.snowflake_stealer"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { ff7004 e8???????? 58 59 eb19 8d5c2424 89f2 }
            // n = 7, score = 100
            //   ff7004               | push                dword ptr [eax + 4]
            //   e8????????           |                     
            //   58                   | pop                 eax
            //   59                   | pop                 ecx
            //   eb19                 | jmp                 0x1b
            //   8d5c2424             | lea                 ebx, [esp + 0x24]
            //   89f2                 | mov                 edx, esi

        $sequence_1 = { ff7510 50 e8???????? 8b450c 83c40c 8906 8b442414 }
            // n = 7, score = 100
            //   ff7510               | push                dword ptr [ebp + 0x10]
            //   50                   | push                eax
            //   e8????????           |                     
            //   8b450c               | mov                 eax, dword ptr [ebp + 0xc]
            //   83c40c               | add                 esp, 0xc
            //   8906                 | mov                 dword ptr [esi], eax
            //   8b442414             | mov                 eax, dword ptr [esp + 0x14]

        $sequence_2 = { ebe6 0fb6c0 8971fc 8941f8 5e 5f 5b }
            // n = 7, score = 100
            //   ebe6                 | jmp                 0xffffffe8
            //   0fb6c0               | movzx               eax, al
            //   8971fc               | mov                 dword ptr [ecx - 4], esi
            //   8941f8               | mov                 dword ptr [ecx - 8], eax
            //   5e                   | pop                 esi
            //   5f                   | pop                 edi
            //   5b                   | pop                 ebx

        $sequence_3 = { ff742404 e8???????? 59 e9???????? 83ec20 53 55 }
            // n = 7, score = 100
            //   ff742404             | push                dword ptr [esp + 4]
            //   e8????????           |                     
            //   59                   | pop                 ecx
            //   e9????????           |                     
            //   83ec20               | sub                 esp, 0x20
            //   53                   | push                ebx
            //   55                   | push                ebp

        $sequence_4 = { f20f100d???????? 89c7 89d3 f20f115008 f20f1100 f20f11480e 6a0c }
            // n = 7, score = 100
            //   f20f100d????????     |                     
            //   89c7                 | mov                 edi, eax
            //   89d3                 | mov                 ebx, edx
            //   f20f115008           | movsd               qword ptr [eax + 8], xmm2
            //   f20f1100             | movsd               qword ptr [eax], xmm0
            //   f20f11480e           | movsd               qword ptr [eax + 0xe], xmm1
            //   6a0c                 | push                0xc

        $sequence_5 = { ff742450 e8???????? 6af7 57 8b7c245c 8bf0 57 }
            // n = 7, score = 100
            //   ff742450             | push                dword ptr [esp + 0x50]
            //   e8????????           |                     
            //   6af7                 | push                -9
            //   57                   | push                edi
            //   8b7c245c             | mov                 edi, dword ptr [esp + 0x5c]
            //   8bf0                 | mov                 esi, eax
            //   57                   | push                edi

        $sequence_6 = { ebf3 31c0 39c7 740d 803c0100 784f 40 }
            // n = 7, score = 100
            //   ebf3                 | jmp                 0xfffffff5
            //   31c0                 | xor                 eax, eax
            //   39c7                 | cmp                 edi, eax
            //   740d                 | je                  0xf
            //   803c0100             | cmp                 byte ptr [ecx + eax], 0
            //   784f                 | js                  0x51
            //   40                   | inc                 eax

        $sequence_7 = { ff500c 83c40c 8d742408 89e2 893e 884608 83660400 }
            // n = 7, score = 100
            //   ff500c               | call                dword ptr [eax + 0xc]
            //   83c40c               | add                 esp, 0xc
            //   8d742408             | lea                 esi, [esp + 8]
            //   89e2                 | mov                 edx, esp
            //   893e                 | mov                 dword ptr [esi], edi
            //   884608               | mov                 byte ptr [esi + 8], al
            //   83660400             | and                 dword ptr [esi + 4], 0

        $sequence_8 = { ffb42498000000 e8???????? 58 8d442418 8b6c2414 837c241001 f20f1000 }
            // n = 7, score = 100
            //   ffb42498000000       | push                dword ptr [esp + 0x98]
            //   e8????????           |                     
            //   58                   | pop                 eax
            //   8d442418             | lea                 eax, [esp + 0x18]
            //   8b6c2414             | mov                 ebp, dword ptr [esp + 0x14]
            //   837c241001           | cmp                 dword ptr [esp + 0x10], 1
            //   f20f1000             | movsd               xmm0, qword ptr [eax]

        $sequence_9 = { ff2485aa2a5500 8a4601 8bca 89542428 84c0 741b 3c3a }
            // n = 7, score = 100
            //   ff2485aa2a5500       | jmp                 dword ptr [eax*4 + 0x552aaa]
            //   8a4601               | mov                 al, byte ptr [esi + 1]
            //   8bca                 | mov                 ecx, edx
            //   89542428             | mov                 dword ptr [esp + 0x28], edx
            //   84c0                 | test                al, al
            //   741b                 | je                  0x1d
            //   3c3a                 | cmp                 al, 0x3a

    condition:
        7 of them and filesize < 6196224
}
Download all Yara Rules