SYMBOLCOMMON_NAMEaka. SYNONYMS
win.zeus_openssl (Back to overview)

Zeus OpenSSL

aka: XSphinx
VTCollection    

This family describes the Zeus-variant that includes a version of OpenSSL and usually is downloaded by Zloader.

In June 2016, the version 1.5.4.0 (PE timestamp: 2016.05.11) appeared, downloaded by Zloader (known as DEloader at that time). OpenSSL 1.0.1p is statically linked to it, thus its size is roughly 1.2 MB. In subsequent months, that size increased up to 1.6 MB.
In January 2017, with version 1.14.8.0, OpenSSL 1.0.2j was linked to it, increasing the size to 1.8 MB. Soon after also in January 2017, with version v1.15.0.0 the code was obfuscated, blowing up the size of the binary to 2.2 MB.

Please note that IBM X-Force decided to call win.zloader/win.zeus_openssl "Zeus Sphinx", after mentioning it as "a new version of Zeus Sphinx" in their initial post in August 2016. Malpedia thus lists the alias "Zeus XSphinx" for win.zeus_openssl - the X to refer to IBM X-Force.

Zeus Sphinx on the one hand has the following versioning ("slow increase")
- 2015/09 v1.0.1.0 (Zeus Sphinx size: 1.5 MB)
- 2016/02 v1.0.1.2 (Zeus Sphinx size: 1.5 MB)
- 2016/04 v1.0.2.0 (Zeus Sphinx size: 1.5 MB)

Zeus OpenSSL on the other hand has the following versioning ("fast increase")
- 2016/05 v1.5.4.0 (Zeus OpenSSL size: 1.2 MB)
- 2017/01 v1.14.8.0 (Zeus OpenSSL size: 1.8 MB)
- 2017/01 v1.15.0.0 (Zeus OpenSSL size: 2.2 MB)

References
2020-03-30 ⋅ IBM ⋅ Amir Gandler, Limor Kessem
Zeus Sphinx Trojan Awakens Amidst Coronavirus Spam Frenzy
Zeus OpenSSL Zloader
2016-08-16 ⋅ SecurityIntelligence ⋅ Denis Laskov, Limor Kessem, Ziv Eli
Brazil Can’t Catch a Break: After Panda Comes the Sphinx
Zeus OpenSSL
Yara Rules
[TLP:WHITE] win_zeus_openssl_auto (20260917 | Detects win.zeus_openssl.)
rule win_zeus_openssl_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.zeus_openssl."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.zeus_openssl"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8975f8 c745ec00000000 81fb3d020000 0f8d9f010000 8d815c0b0000 ba3d020000 2bd3 }
            // n = 7, score = 1300
            //   8975f8               | mov                 dword ptr [ebp - 8], esi
            //   c745ec00000000       | mov                 dword ptr [ebp - 0x14], 0
            //   81fb3d020000         | cmp                 ebx, 0x23d
            //   0f8d9f010000         | jge                 0x1a5
            //   8d815c0b0000         | lea                 eax, [ecx + 0xb5c]
            //   ba3d020000           | mov                 edx, 0x23d
            //   2bd3                 | sub                 edx, ebx

        $sequence_1 = { 814a1800900000 5e a810 7444 a840 741f }
            // n = 6, score = 1300
            //   814a1800900000       | or                  dword ptr [edx + 0x18], 0x9000
            //   5e                   | pop                 esi
            //   a810                 | test                al, 0x10
            //   7444                 | je                  0x46
            //   a840                 | test                al, 0x40
            //   741f                 | je                  0x21

        $sequence_2 = { f6c510 7405 80cd08 eb03 80e5f7 886dff }
            // n = 6, score = 1300
            //   f6c510               | test                ch, 0x10
            //   7405                 | je                  7
            //   80cd08               | or                  ch, 8
            //   eb03                 | jmp                 5
            //   80e5f7               | and                 ch, 0xf7
            //   886dff               | mov                 byte ptr [ebp - 1], ch

        $sequence_3 = { 66d3ef 83c0f5 6689beb8160000 eb11 8b4508 48 66d3e0 }
            // n = 7, score = 1300
            //   66d3ef               | shr                 di, cl
            //   83c0f5               | add                 eax, -0xb
            //   6689beb8160000       | mov                 word ptr [esi + 0x16b8], di
            //   eb11                 | jmp                 0x13
            //   8b4508               | mov                 eax, dword ptr [ebp + 8]
            //   48                   | dec                 eax
            //   66d3e0               | shl                 ax, cl

        $sequence_4 = { 33c9 83e20f 7614 0fb6440e18 0306 3985e8fdffff 7449 }
            // n = 7, score = 1300
            //   33c9                 | xor                 ecx, ecx
            //   83e20f               | and                 edx, 0xf
            //   7614                 | jbe                 0x16
            //   0fb6440e18           | movzx               eax, byte ptr [esi + ecx + 0x18]
            //   0306                 | add                 eax, dword ptr [esi]
            //   3985e8fdffff         | cmp                 dword ptr [ebp - 0x218], eax
            //   7449                 | je                  0x4b

        $sequence_5 = { f6c510 7405 80cd08 eb03 80e5f7 886dff 0fb6f9 }
            // n = 7, score = 1300
            //   f6c510               | test                ch, 0x10
            //   7405                 | je                  7
            //   80cd08               | or                  ch, 8
            //   eb03                 | jmp                 5
            //   80e5f7               | and                 ch, 0xf7
            //   886dff               | mov                 byte ptr [ebp - 1], ch
            //   0fb6f9               | movzx               edi, cl

        $sequence_6 = { 837e6800 0f8443010000 8b4e6c 8b4638 33ff 8a5401ff 8b8ea0160000 }
            // n = 7, score = 1300
            //   837e6800             | cmp                 dword ptr [esi + 0x68], 0
            //   0f8443010000         | je                  0x149
            //   8b4e6c               | mov                 ecx, dword ptr [esi + 0x6c]
            //   8b4638               | mov                 eax, dword ptr [esi + 0x38]
            //   33ff                 | xor                 edi, edi
            //   8a5401ff             | mov                 dl, byte ptr [ecx + eax - 1]
            //   8b8ea0160000         | mov                 ecx, dword ptr [esi + 0x16a0]

        $sequence_7 = { 814a1800300000 8a6207 84e4 7543 8ac1 }
            // n = 5, score = 1300
            //   814a1800300000       | or                  dword ptr [edx + 0x18], 0x3000
            //   8a6207               | mov                 ah, byte ptr [edx + 7]
            //   84e4                 | test                ah, ah
            //   7543                 | jne                 0x45
            //   8ac1                 | mov                 al, cl

        $sequence_8 = { 8986bc160000 83f90c 7e52 8b7d0c 8b5614 83c7fc 668bc7 }
            // n = 7, score = 1300
            //   8986bc160000         | mov                 dword ptr [esi + 0x16bc], eax
            //   83f90c               | cmp                 ecx, 0xc
            //   7e52                 | jle                 0x54
            //   8b7d0c               | mov                 edi, dword ptr [ebp + 0xc]
            //   8b5614               | mov                 edx, dword ptr [esi + 0x14]
            //   83c7fc               | add                 edi, -4
            //   668bc7               | mov                 ax, di

        $sequence_9 = { 83e20f 7614 0fb6440e18 0306 }
            // n = 4, score = 1300
            //   83e20f               | and                 edx, 0xf
            //   7614                 | jbe                 0x16
            //   0fb6440e18           | movzx               eax, byte ptr [esi + ecx + 0x18]
            //   0306                 | add                 eax, dword ptr [esi]

    condition:
        7 of them and filesize < 4546560
}
Download all Yara Rules