There is no description at this point.
rule win_xfilesstealer_auto { meta: author = "Felix Bilstein - yara-signator at cocacoding dot com" date = "2026-09-17" version = "1" description = "Detects win.xfilesstealer." info = "autogenerated rule brought to you by yara-signator" tool = "yara-signator v0.6.0" signator_config = "callsandjumps;datarefs;binvalue" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xfilesstealer" malpedia_rule_date = "20260916" malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6" malpedia_version = "20260917" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" /* DISCLAIMER * The strings used in this rule have been automatically selected from the * disassembly of memory dumps and unpacked files, using YARA-Signator. * The code and documentation is published here: * https://github.com/fxb-cocacoding/yara-signator * As Malpedia is used as data source, please note that for a given * number of families, only single samples are documented. * This likely impacts the degree of generalization these rules will offer. * Take the described generation method also into consideration when you * apply the rules in your use cases and assign them confidence levels. */ strings: $sequence_0 = { ffd3 488bf8 4885c0 74ce 488bc8 e8???????? 488bd8 } // n = 7, score = 100 // ffd3 | mov eax, dword ptr [edi] // 488bf8 | dec eax // 4885c0 | mov ebx, dword ptr [eax + 0x38] // 74ce | dec eax // 488bc8 | mov ecx, ebx // e8???????? | // 488bd8 | mov eax, 1 $sequence_1 = { ff15???????? 488d55df 488bcf ffd3 448bf0 498b4f20 397118 } // n = 7, score = 100 // ff15???????? | // 488d55df | test ebx, ebx // 488bcf | je 0xac3 // ffd3 | dec eax // 448bf0 | lea ecx, [ebx - 0x1030] // 498b4f20 | dec eax // 397118 | and dword ptr [ecx + 0x1058], 0 $sequence_2 = { ffd3 8bc8 e8???????? 488b942440030000 448b4c2434 41ffc4 4489642474 } // n = 7, score = 100 // ffd3 | dec eax // 8bc8 | mov dword ptr [ebx + 0x98], eax // e8???????? | // 488b942440030000 | mov eax, 5 // 448b4c2434 | mov eax, 0x64 // 41ffc4 | sub eax, edx // 4489642474 | mov ecx, 0x10 $sequence_3 = { ffe1 4983f9ff 41b827000000 488bda 4c0f44ca e9???????? 4983f9ff } // n = 7, score = 100 // ffe1 | inc si // 4983f9ff | mov dword ptr [edi + esi*2], edi // 41b827000000 | dec eax // 488bda | or edx, 0xffffffff // 4c0f44ca | dec eax // e9???????? | // 4983f9ff | inc edx $sequence_4 = { ffd3 458bf5 488b4608 4883e0fe 48874608 eb09 41bf01000000 } // n = 7, score = 100 // ffd3 | mov dword ptr [esp + 0x60], ecx // 458bf5 | mov al, 1 // 488b4608 | jmp 0x97d // 4883e0fe | xor al, al // 48874608 | movzx ecx, al // eb09 | dec eax // 41bf01000000 | lea ecx, [0x17c5f1] $sequence_5 = { ffd3 4c63c0 48c744243080060000 4c89442428 48c744242020205248 4c8d0dee771b00 ba00400000 } // n = 7, score = 100 // ffd3 | add esp, 0x20 // 4c63c0 | pop edi // 48c744243080060000 | mov eax, 1 // 4c89442428 | dec eax // 48c744242020205248 | mov ebx, dword ptr [esp + 0x30] // 4c8d0dee771b00 | dec eax // ba00400000 | add esp, 0x20 $sequence_6 = { ffd3 488b7d30 4885ff 7415 488b07 488b5810 488bcb } // n = 7, score = 100 // ffd3 | mov ecx, ebx // 488b7d30 | dec eax // 4885ff | mov ecx, ebx // 7415 | mov dl, 0x52 // 488b07 | dec eax // 488b5810 | mov ecx, ebx // 488bcb | dec eax $sequence_7 = { ffd3 85c0 753b 0f1045bf 0f114587 0f1045cf 0f114597 } // n = 7, score = 100 // ffd3 | dec eax // 85c0 | add eax, 0xc // 753b | dec eax // 0f1045bf | cmp eax, 0x10 // 0f114587 | jne 0x183b // 0f1045cf | mov eax, 0x8007000e // 0f114597 | jmp 0x180b $sequence_8 = { ff15???????? 4c8d4e08 4c8bc6 8bd5 498bce ffd7 8bd8 } // n = 7, score = 100 // ff15???????? | // 4c8d4e08 | dec eax // 4c8bc6 | lea ecx, [esp + 0x50] // 8bd5 | jmp 0x895 // 498bce | nop // ffd7 | dec eax // 8bd8 | lea ecx, [esp + 0x30] $sequence_9 = { ffd7 488bc8 c744242803000000 48895c2420 4d8bcc 4d8bc6 498bd7 } // n = 7, score = 100 // ffd7 | mov dword ptr [esp + 0x28], 1 // 488bc8 | mov word ptr [esp + 0x20], cx // c744242803000000 | dec esp // 48895c2420 | lea ecx, [ebp - 0x39] // 4d8bcc | dec esp // 4d8bc6 | lea eax, [ebp - 0x29] // 498bd7 | mov ecx, 0x2c condition: 7 of them and filesize < 20821780 }
rule win_xfilesstealer_w0 { meta: author = "Johannes Bader @viql" date = "2022-04-15" version = "v1.0" description = "detects XFiles-Stealer" hash = "d06072f959d895f2fc9a57f44bf6357596c5c3410e90dabe06b171161f37d690" tlp = "TLP:WHITE" malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.xfilesstealer" malpedia_rule_date = "20220425" malpedia_hash = "" malpedia_version = "20220425" malpedia_license = "CC BY-SA 4.0" malpedia_sharing = "TLP:WHITE" strings: $ad_1 = "Telegram bot - @XFILESShop_Bot" wide $ad_2 = "Telegram support - @XFILES_Seller" wide $names_1 = "XFiles.Models.Yeti" $names_2 = "anti_vzlom_popki" // анти взлом попки $names_3 = "assType" $names_4 = "hackrjaw" $upload_1 = "zipx" wide $upload_2 = "user_id" wide $upload_3 = "passworlds_x" wide $upload_4 = "ip_x" wide $upload_5 = "cc_x" wide $upload_6 = "cookies_x" wide $upload_7 = "zip_x" wide $upload_8 = "contry_x" wide $upload_9 = "tag_x" wide $upload_10 = "piece" wide condition: uint16(0) == 0x5A4D and ( all of ($ad_*) or all of ($names_*) or all of ($upload_*) ) }
If your designated proposal does not fit in any other category, feel free to write a free-text in the comment field below. Changes regarding references should be proposed on the Malpedia library page.
Your suggestion will be reviewed before being published. Thank you for contributing!
YYYY-MM-DD
YYYY-MM
YYYY