SYMBOLCOMMON_NAMEaka. SYNONYMS
win.httpbrowser (Back to overview)

HttpBrowser

aka: HttpDump

Actor(s): Wekby, EMISSARY PANDA

VTCollection    

There is no description at this point.

References
2020-01-01 ⋅ Secureworks ⋅ SecureWorks
BRONZE UNION
9002 RAT CHINACHOPPER Enfal Ghost RAT HttpBrowser HyperBro owaauth PlugX Poison Ivy ZXShell APT27
2018-05-18 ⋅ NCC Group ⋅ Nikolaos Pantazopoulos, Thomas Henry
Emissary Panda – A potential new malicious tool
HttpBrowser
2017-05-31 ⋅ MITRE ⋅ MITRE
APT18
Ghost RAT HttpBrowser APT18
2016-10-17 ⋅ ThreatConnect ⋅ ThreatConnect
A Tale of Two Targets
HttpBrowser APT27
2015-02-27 ⋅ ThreatConnect ⋅ ThreatConnect Research Team
The Anthem Hack: All Roads Lead to China
HttpBrowser
2015-02-06 ⋅ CrowdStrike ⋅ CrowdStrike
CrowdStrike Global Threat Intel Report 2014
BlackPOS CryptoLocker Derusbi Elise Enfal EvilGrab Gameover P2P HttpBrowser MedusaHTTP Mirage Naikon NetTraveler pirpi PlugX Poison Ivy Sakula RAT Sinowal sykipot taidoor
Yara Rules
[TLP:WHITE] win_httpbrowser_auto (20260917 | Detects win.httpbrowser.)
rule win_httpbrowser_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.httpbrowser."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.httpbrowser"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 50 ff15???????? 6a05 58 56 }
            // n = 5, score = 200
            //   50                   | push                eax
            //   ff15????????         |                     
            //   6a05                 | push                5
            //   58                   | pop                 eax
            //   56                   | push                esi

        $sequence_1 = { 740e ffb59cfeffff ffd6 89bd9cfeffff 39bda0feffff }
            // n = 5, score = 200
            //   740e                 | je                  0x10
            //   ffb59cfeffff         | push                dword ptr [ebp - 0x164]
            //   ffd6                 | call                esi
            //   89bd9cfeffff         | mov                 dword ptr [ebp - 0x164], edi
            //   39bda0feffff         | cmp                 dword ptr [ebp - 0x160], edi

        $sequence_2 = { 59 8d85d4f7ffff 50 8d85dcf9ffff }
            // n = 4, score = 200
            //   59                   | pop                 ecx
            //   8d85d4f7ffff         | lea                 eax, [ebp - 0x82c]
            //   50                   | push                eax
            //   8d85dcf9ffff         | lea                 eax, [ebp - 0x624]

        $sequence_3 = { ffd6 8b45fc 33c9 66890c78 5f 5e 5b }
            // n = 7, score = 200
            //   ffd6                 | call                esi
            //   8b45fc               | mov                 eax, dword ptr [ebp - 4]
            //   33c9                 | xor                 ecx, ecx
            //   66890c78             | mov                 word ptr [eax + edi*2], cx
            //   5f                   | pop                 edi
            //   5e                   | pop                 esi
            //   5b                   | pop                 ebx

        $sequence_4 = { 8985f4edffff 33c0 68fe010000 50 }
            // n = 4, score = 200
            //   8985f4edffff         | mov                 dword ptr [ebp - 0x120c], eax
            //   33c0                 | xor                 eax, eax
            //   68fe010000           | push                0x1fe
            //   50                   | push                eax

        $sequence_5 = { 8d857afbffff 53 50 e8???????? 83c40c 33c0 6a7e }
            // n = 7, score = 200
            //   8d857afbffff         | lea                 eax, [ebp - 0x486]
            //   53                   | push                ebx
            //   50                   | push                eax
            //   e8????????           |                     
            //   83c40c               | add                 esp, 0xc
            //   33c0                 | xor                 eax, eax
            //   6a7e                 | push                0x7e

        $sequence_6 = { 89855053ffff 83f8ff 0f841f020000 bb00040000 eb02 33ff 8b35???????? }
            // n = 7, score = 200
            //   89855053ffff         | mov                 dword ptr [ebp - 0xacb0], eax
            //   83f8ff               | cmp                 eax, -1
            //   0f841f020000         | je                  0x225
            //   bb00040000           | mov                 ebx, 0x400
            //   eb02                 | jmp                 4
            //   33ff                 | xor                 edi, edi
            //   8b35????????         |                     

        $sequence_7 = { 8d85eefdffff 56 50 e8???????? 8d85ecfdffff }
            // n = 5, score = 200
            //   8d85eefdffff         | lea                 eax, [ebp - 0x212]
            //   56                   | push                esi
            //   50                   | push                eax
            //   e8????????           |                     
            //   8d85ecfdffff         | lea                 eax, [ebp - 0x214]

        $sequence_8 = { c3 50 50 9c b80a000000 51 b932000000 }
            // n = 7, score = 100
            //   c3                   | ret                 
            //   50                   | push                eax
            //   50                   | push                eax
            //   9c                   | pushfd              
            //   b80a000000           | mov                 eax, 0xa
            //   51                   | push                ecx
            //   b932000000           | mov                 ecx, 0x32

        $sequence_9 = { 9d 58 8b45f8 50 ff15???????? 8b45f4 }
            // n = 6, score = 100
            //   9d                   | popfd               
            //   58                   | pop                 eax
            //   8b45f8               | mov                 eax, dword ptr [ebp - 8]
            //   50                   | push                eax
            //   ff15????????         |                     
            //   8b45f4               | mov                 eax, dword ptr [ebp - 0xc]

        $sequence_10 = { 6a5c 52 66c7000000 e8???????? 50 }
            // n = 5, score = 100
            //   6a5c                 | push                0x5c
            //   52                   | push                edx
            //   66c7000000           | mov                 word ptr [eax], 0
            //   e8????????           |                     
            //   50                   | push                eax

        $sequence_11 = { 8b4510 8b55f0 8b4d14 03c2 3bc1 894510 }
            // n = 6, score = 100
            //   8b4510               | mov                 eax, dword ptr [ebp + 0x10]
            //   8b55f0               | mov                 edx, dword ptr [ebp - 0x10]
            //   8b4d14               | mov                 ecx, dword ptr [ebp + 0x14]
            //   03c2                 | add                 eax, edx
            //   3bc1                 | cmp                 eax, ecx
            //   894510               | mov                 dword ptr [ebp + 0x10], eax

        $sequence_12 = { 33c0 8dbda1edffff 8895a0edffff f3ab 66ab }
            // n = 5, score = 100
            //   33c0                 | xor                 eax, eax
            //   8dbda1edffff         | lea                 edi, [ebp - 0x125f]
            //   8895a0edffff         | mov                 byte ptr [ebp - 0x1260], dl
            //   f3ab                 | rep stosd           dword ptr es:[edi], eax
            //   66ab                 | stosw               word ptr es:[edi], ax

        $sequence_13 = { 7422 66891f 83c702 57 }
            // n = 4, score = 100
            //   7422                 | je                  0x24
            //   66891f               | mov                 word ptr [edi], bx
            //   83c702               | add                 edi, 2
            //   57                   | push                edi

        $sequence_14 = { 81ec04020000 53 56 57 33d2 }
            // n = 5, score = 100
            //   81ec04020000         | sub                 esp, 0x204
            //   53                   | push                ebx
            //   56                   | push                esi
            //   57                   | push                edi
            //   33d2                 | xor                 edx, edx

        $sequence_15 = { ff15???????? 8b750c 68000000a0 8d9514f5ffff 50 }
            // n = 5, score = 100
            //   ff15????????         |                     
            //   8b750c               | mov                 esi, dword ptr [ebp + 0xc]
            //   68000000a0           | push                0xa0000000
            //   8d9514f5ffff         | lea                 edx, [ebp - 0xaec]
            //   50                   | push                eax

    condition:
        7 of them and filesize < 188416
}
Download all Yara Rules