SYMBOLCOMMON_NAMEaka. SYNONYMS
win.hazy_load (Back to overview)

HazyLoad

Actor(s): Silent Chollima

VTCollection    

There is no description at this point.

References
2023-12-11 ⋅ Cisco Talos ⋅ Asheer Malhotra, Jungsoo An, Vitor Ventura
Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang
BottomLoader DLRAT HazyLoad NineRAT
2023-10-18 ⋅ Microsoft ⋅ Microsoft Threat Intelligence
Multiple North Korean threat actors exploiting the TeamCity CVE-2023-42793 vulnerability
FeedLoad ForestTiger HazyLoad RollSling Silent Chollima
2023-02-23 ⋅ Symantec ⋅ Threat Hunter Team
Clasiopa: New Group Targets Materials Research
Atharvan HazyLoad Lilith
Yara Rules
[TLP:WHITE] win_hazy_load_auto (20260917 | Detects win.hazy_load.)
rule win_hazy_load_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.hazy_load."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.hazy_load"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 33c0 f04d0fb1bcf130100200 488bd8 740e }
            // n = 4, score = 200
            //   33c0                 | mov                 ebx, dword ptr [esp + 0x260]
            //   f04d0fb1bcf130100200     | dec    eax
            //   488bd8               | mov                 ecx, dword ptr [esp + 0x240]
            //   740e                 | dec                 eax

        $sequence_1 = { 488945f0 488d1594c40000 b805000000 894520 894528 }
            // n = 5, score = 200
            //   488945f0             | inc                 edx
            //   488d1594c40000       | movzx               eax, byte ptr [ebx + eax]
            //   b805000000           | inc                 edx
            //   894520               | mov                 byte ptr [ecx + eax], al
            //   894528               | dec                 ebp

        $sequence_2 = { f00fc103 83f801 7516 488d05b5330100 488b4c2430 483bc8 7405 }
            // n = 7, score = 200
            //   f00fc103             | dec                 eax
            //   83f801               | lea                 ecx, [0xfe46]
            //   7516                 | mov                 dword ptr [ebx + 0x50], 6
            //   488d05b5330100       | dec                 eax
            //   488b4c2430           | mov                 dword ptr [ebx + 0x48], ecx
            //   483bc8               | mov                 byte ptr [ebx + 0x54], 0
            //   7405                 | dec                 eax

        $sequence_3 = { 488b442448 4883f8ff 74c8 488bd3 4c8d05ceed0000 83e23f }
            // n = 6, score = 200
            //   488b442448           | add                 eax, eax
            //   4883f8ff             | dec                 eax
            //   74c8                 | lea                 ecx, [0x205e3]
            //   488bd3               | dec                 eax
            //   4c8d05ceed0000       | mov                 dword ptr [ebp + eax*8], ebx
            //   83e23f               | mov                 byte ptr [ebp + eax*8 + 8], 1

        $sequence_4 = { 488d0d12c9ffff 4933f8 4a87bcf150100200 33c0 488b5c2450 488b6c2458 488b742460 }
            // n = 7, score = 200
            //   488d0d12c9ffff       | dec                 eax
            //   4933f8               | sub                 esp, 0x20
            //   4a87bcf150100200     | mov                 esi, edx
            //   33c0                 | dec                 esp
            //   488b5c2450           | lea                 ecx, [0xc3a4]
            //   488b6c2458           | dec                 eax
            //   488b742460           | mov                 ebx, ecx

        $sequence_5 = { 8d41ff 8b8482f89e0100 85c0 0f8489000000 }
            // n = 4, score = 200
            //   8d41ff               | je                  0x1bf
            //   8b8482f89e0100       | test                ebx, ebx
            //   85c0                 | jne                 0x1bf
            //   0f8489000000         | dec                 eax

        $sequence_6 = { 488d0d5beffeff 48c1e602 0fb784b9609e0100 488d9150950100 }
            // n = 4, score = 200
            //   488d0d5beffeff       | mov                 eax, edx
            //   48c1e602             | dec                 eax
            //   0fb784b9609e0100     | mov                 ecx, edx
            //   488d9150950100       | dec                 esp

        $sequence_7 = { 448bc7 4863c3 488d5504 442bc3 }
            // n = 4, score = 200
            //   448bc7               | dec                 eax
            //   4863c3               | mov                 ecx, ebp
            //   488d5504             | xor                 eax, eax
            //   442bc3               | inc                 ecx

        $sequence_8 = { 442bc3 4803d0 4533c9 488bce ff15???????? 85c0 0f8eacfeffff }
            // n = 7, score = 200
            //   442bc3               | dec                 esp
            //   4803d0               | lea                 edi, [0x2065e]
            //   4533c9               | nop                 dword ptr [eax]
            //   488bce               | nop                 word ptr [eax + eax]
            //   ff15????????         |                     
            //   85c0                 | xor                 edx, edx
            //   0f8eacfeffff         | dec                 eax

        $sequence_9 = { eb75 4c8bf3 488d3513be0100 488d2df4bd0100 }
            // n = 4, score = 200
            //   eb75                 | cmp                 ebx, 2
            //   4c8bf3               | sete                al
            //   488d3513be0100       | dec                 eax
            //   488d2df4bd0100       | mov                 ecx, dword ptr [esp + 0x50]

    condition:
        7 of them and filesize < 315392
}
Download all Yara Rules