SYMBOLCOMMON_NAMEaka. SYNONYMS
win.xfilesstealer (Back to overview)

X-Files Stealer

VTCollection    

There is no description at this point.

References
2022-08-04 ⋅ Zscaler ⋅ Stuti Chaturvedi
X-FILES Stealer Evolution - An Analysis and Comparison Study
X-Files Stealer
2022-07-03 ⋅ CyberInt ⋅ CyberInt, Shmuel Gihon
XFiles Stealer Campaign Abusing Follina
X-Files Stealer
2021-12-25 ⋅ 3xp0rt ⋅ 3xp0rt
A new version of X-Files Stealer
X-Files Stealer
Yara Rules
[TLP:WHITE] win_xfilesstealer_auto (20260917 | Detects win.xfilesstealer.)
rule win_xfilesstealer_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.xfilesstealer."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xfilesstealer"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { ffd3 488bf8 4885c0 74ce 488bc8 e8???????? 488bd8 }
            // n = 7, score = 100
            //   ffd3                 | mov                 eax, dword ptr [edi]
            //   488bf8               | dec                 eax
            //   4885c0               | mov                 ebx, dword ptr [eax + 0x38]
            //   74ce                 | dec                 eax
            //   488bc8               | mov                 ecx, ebx
            //   e8????????           |                     
            //   488bd8               | mov                 eax, 1

        $sequence_1 = { ff15???????? 488d55df 488bcf ffd3 448bf0 498b4f20 397118 }
            // n = 7, score = 100
            //   ff15????????         |                     
            //   488d55df             | test                ebx, ebx
            //   488bcf               | je                  0xac3
            //   ffd3                 | dec                 eax
            //   448bf0               | lea                 ecx, [ebx - 0x1030]
            //   498b4f20             | dec                 eax
            //   397118               | and                 dword ptr [ecx + 0x1058], 0

        $sequence_2 = { ffd3 8bc8 e8???????? 488b942440030000 448b4c2434 41ffc4 4489642474 }
            // n = 7, score = 100
            //   ffd3                 | dec                 eax
            //   8bc8                 | mov                 dword ptr [ebx + 0x98], eax
            //   e8????????           |                     
            //   488b942440030000     | mov                 eax, 5
            //   448b4c2434           | mov                 eax, 0x64
            //   41ffc4               | sub                 eax, edx
            //   4489642474           | mov                 ecx, 0x10

        $sequence_3 = { ffe1 4983f9ff 41b827000000 488bda 4c0f44ca e9???????? 4983f9ff }
            // n = 7, score = 100
            //   ffe1                 | inc                 si
            //   4983f9ff             | mov                 dword ptr [edi + esi*2], edi
            //   41b827000000         | dec                 eax
            //   488bda               | or                  edx, 0xffffffff
            //   4c0f44ca             | dec                 eax
            //   e9????????           |                     
            //   4983f9ff             | inc                 edx

        $sequence_4 = { ffd3 458bf5 488b4608 4883e0fe 48874608 eb09 41bf01000000 }
            // n = 7, score = 100
            //   ffd3                 | mov                 dword ptr [esp + 0x60], ecx
            //   458bf5               | mov                 al, 1
            //   488b4608             | jmp                 0x97d
            //   4883e0fe             | xor                 al, al
            //   48874608             | movzx               ecx, al
            //   eb09                 | dec                 eax
            //   41bf01000000         | lea                 ecx, [0x17c5f1]

        $sequence_5 = { ffd3 4c63c0 48c744243080060000 4c89442428 48c744242020205248 4c8d0dee771b00 ba00400000 }
            // n = 7, score = 100
            //   ffd3                 | add                 esp, 0x20
            //   4c63c0               | pop                 edi
            //   48c744243080060000     | mov    eax, 1
            //   4c89442428           | dec                 eax
            //   48c744242020205248     | mov    ebx, dword ptr [esp + 0x30]
            //   4c8d0dee771b00       | dec                 eax
            //   ba00400000           | add                 esp, 0x20

        $sequence_6 = { ffd3 488b7d30 4885ff 7415 488b07 488b5810 488bcb }
            // n = 7, score = 100
            //   ffd3                 | mov                 ecx, ebx
            //   488b7d30             | dec                 eax
            //   4885ff               | mov                 ecx, ebx
            //   7415                 | mov                 dl, 0x52
            //   488b07               | dec                 eax
            //   488b5810             | mov                 ecx, ebx
            //   488bcb               | dec                 eax

        $sequence_7 = { ffd3 85c0 753b 0f1045bf 0f114587 0f1045cf 0f114597 }
            // n = 7, score = 100
            //   ffd3                 | dec                 eax
            //   85c0                 | add                 eax, 0xc
            //   753b                 | dec                 eax
            //   0f1045bf             | cmp                 eax, 0x10
            //   0f114587             | jne                 0x183b
            //   0f1045cf             | mov                 eax, 0x8007000e
            //   0f114597             | jmp                 0x180b

        $sequence_8 = { ff15???????? 4c8d4e08 4c8bc6 8bd5 498bce ffd7 8bd8 }
            // n = 7, score = 100
            //   ff15????????         |                     
            //   4c8d4e08             | dec                 eax
            //   4c8bc6               | lea                 ecx, [esp + 0x50]
            //   8bd5                 | jmp                 0x895
            //   498bce               | nop                 
            //   ffd7                 | dec                 eax
            //   8bd8                 | lea                 ecx, [esp + 0x30]

        $sequence_9 = { ffd7 488bc8 c744242803000000 48895c2420 4d8bcc 4d8bc6 498bd7 }
            // n = 7, score = 100
            //   ffd7                 | mov                 dword ptr [esp + 0x28], 1
            //   488bc8               | mov                 word ptr [esp + 0x20], cx
            //   c744242803000000     | dec                 esp
            //   48895c2420           | lea                 ecx, [ebp - 0x39]
            //   4d8bcc               | dec                 esp
            //   4d8bc6               | lea                 eax, [ebp - 0x29]
            //   498bd7               | mov                 ecx, 0x2c

    condition:
        7 of them and filesize < 20821780
}
[TLP:WHITE] win_xfilesstealer_w0   (20220425 | detects XFiles-Stealer)
rule win_xfilesstealer_w0 {

    meta:
        author      = "Johannes Bader @viql"
        date        = "2022-04-15"
        version     = "v1.0"
        description = "detects XFiles-Stealer"
        hash        = "d06072f959d895f2fc9a57f44bf6357596c5c3410e90dabe06b171161f37d690"
        tlp         = "TLP:WHITE"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xfilesstealer"
        malpedia_rule_date = "20220425"
        malpedia_hash = ""
        malpedia_version = "20220425"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    strings:
        $ad_1 = "Telegram bot - @XFILESShop_Bot" wide
        $ad_2 = "Telegram support - @XFILES_Seller" wide

        $names_1 = "XFiles.Models.Yeti"
        $names_2 = "anti_vzlom_popki" // анти взлом попки
        $names_3 = "assType"
        $names_4 = "hackrjaw"

        $upload_1  = "zipx" wide
        $upload_2  = "user_id" wide
        $upload_3  = "passworlds_x" wide
        $upload_4  = "ip_x" wide
        $upload_5  = "cc_x" wide
        $upload_6  = "cookies_x" wide
        $upload_7  = "zip_x" wide
        $upload_8  = "contry_x" wide
        $upload_9  = "tag_x" wide
        $upload_10 = "piece" wide
            
    condition:
        uint16(0) == 0x5A4D and 
        (
            all of ($ad_*) or 
            all of ($names_*) or 
            all of ($upload_*)
        )
}
Download all Yara Rules