SYMBOLCOMMON_NAMEaka. SYNONYMS
win.httpsuploader (Back to overview)

HTTP(S) uploader

Actor(s): Lazarus Group

VTCollection    

The HTTP(S) uploader is a Lazarus tool responsible for data exfiltration, by using the HTTP or HTTPS protocols.

It accepts up to 10 command line parameters: a 29-byte decryption key, a C&C for data exfiltration, the name of a local RAR split volume, the name of the multivolume archive on the server side, the size of a RAR split (max 200,000 kB), the starting index of a split, the ending index of a split, and the switch -p with a proxy IP address and port

References
2022-09-30 ⋅ ESET Research ⋅ Peter Kálnai
Amazon‑themed campaigns of Lazarus in the Netherlands and Belgium
BLINDINGCAN FudModule HTTP(S) uploader LambLoad TOUCHMOVE
2021-02-25 ⋅ Kaspersky Labs ⋅ Seongsu Park, Vyacheslav Kopeytsev
Lazarus targets defense industry with ThreatNeedle
HTTP(S) uploader LPEClient Volgmer
2020-12-15 ⋅ HvS-Consulting AG ⋅ HvS-Consulting AG
Greetings from Lazarus Anatomy of a cyber espionage campaign
BLINDINGCAN HTTP(S) uploader MimiKatz
Yara Rules
[TLP:WHITE] win_httpsuploader_auto (20260917 | Detects win.httpsuploader.)
rule win_httpsuploader_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.httpsuploader."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.httpsuploader"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 85c0 0f850a010000 488b8eb8000000 4c8d25cf7d0000 f0ff09 7511 }
            // n = 6, score = 100
            //   85c0                 | jbe                 0x4cc
            //   0f850a010000         | inc                 ecx
            //   488b8eb8000000       | and                 ecx, 0xf
            //   4c8d25cf7d0000       | movzx               eax, bl
            //   f0ff09               | inc                 ecx
            //   7511                 | shl                 ecx, 2

        $sequence_1 = { 85d2 745e 6666660f1f840000000000 488b0d???????? 488d542440 }
            // n = 5, score = 100
            //   85d2                 | inc                 sp
            //   745e                 | mov                 dword ptr [ecx], ecx
            //   6666660f1f840000000000     | dec    esp
            //   488b0d????????       |                     
            //   488d542440           | mov                 dword ptr [esp + 0x28], ecx

        $sequence_2 = { 4885c0 7415 488b4c2438 4c8d4c2434 }
            // n = 4, score = 100
            //   4885c0               | mov                 ecx, dword ptr [ecx + eax*8]
            //   7415                 | inc                 esp
            //   488b4c2438           | xor                 eax, ecx
            //   4c8d4c2434           | dec                 eax

        $sequence_3 = { 488d54245c 488b88c0000000 488d05f7de0000 395914 4a8b0ce0 }
            // n = 5, score = 100
            //   488d54245c           | jae                 0x131
            //   488b88c0000000       | dec                 eax
            //   488d05f7de0000       | arpl                cx, bx
            //   395914               | dec                 eax
            //   4a8b0ce0             | lea                 ebp, [0xb623]

        $sequence_4 = { 4833c4 4889842420020000 8bf9 33c0 488d4c2422 33d2 }
            // n = 6, score = 100
            //   4833c4               | mov                 byte ptr [ecx], bh
            //   4889842420020000     | inc                 ecx
            //   8bf9                 | cmp                 edi, 0x30d40
            //   33c0                 | ja                  0x985
            //   488d4c2422           | dec                 eax
            //   33d2                 | dec                 ecx

        $sequence_5 = { 8bd6 498bcc e8???????? 85c0 757f 488d8c2470020000 }
            // n = 6, score = 100
            //   8bd6                 | and                 ebx, eax
            //   498bcc               | je                  0x9ef
            //   e8????????           |                     
            //   85c0                 | inc                 ecx
            //   757f                 | mov                 ecx, 0xa0000000
            //   488d8c2470020000     | inc                 ecx

        $sequence_6 = { 4c895d04 66f3ab 488d3d5a840000 482bfd }
            // n = 4, score = 100
            //   4c895d04             | jb                  0x20b
            //   66f3ab               | mov                 ebx, eax
            //   488d3d5a840000       | dec                 eax
            //   482bfd               | mov                 ecx, dword ptr [eax + 0xc0]

        $sequence_7 = { c605????????01 85d2 7430 8bd2 666666660f1f840000000000 }
            // n = 5, score = 100
            //   c605????????01       |                     
            //   85d2                 | lea                 edx, [ebp + 0x4f0]
            //   7430                 | inc                 ecx
            //   8bd2                 | mov                 ecx, 0x3e000000
            //   666666660f1f840000000000     | dec    eax

        $sequence_8 = { 48895c2410 48897c2418 55 488dac2400f3ffff }
            // n = 4, score = 100
            //   48895c2410           | lea                 ecx, [esp + 0x50]
            //   48897c2418           | inc                 ecx
            //   55                   | lea                 edx, [edi + 0x7f]
            //   488dac2400f3ffff     | inc                 ebp

        $sequence_9 = { 85c0 0f84a1000000 488b0d???????? 488d1528ba0000 }
            // n = 4, score = 100
            //   85c0                 | dec                 eax
            //   0f84a1000000         | lea                 ebx, [0xa753]
            //   488b0d????????       |                     
            //   488d1528ba0000       | dec                 eax

    condition:
        7 of them and filesize < 190464
}
Download all Yara Rules