SYMBOLCOMMON_NAMEaka. SYNONYMS
win.pathloader (Back to overview)

PATHLOADER

VTCollection    

There is no description at this point.

References
2025-02-13 ⋅ Elastic ⋅ Cyril François, Daniel Stepanic, Jia Yu Chan, Salim Bitam
You've Got Malware: FINALDRAFT Hides in Your Drafts
FINALDRAFT FINALDRAFT PATHLOADER
2025-02-13 ⋅ Elastic ⋅ Andrew Pease, Seth Goodwin
From South America to Southeast Asia: The Fragile Web of REF7707
FINALDRAFT FINALDRAFT GUIDLOADER PATHLOADER REF7707
Yara Rules
[TLP:WHITE] win_pathloader_auto (20260917 | Detects win.pathloader.)
rule win_pathloader_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.pathloader."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.pathloader"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { c1fa05 8bc2 c1e81f 03d0 0fbec2 6bc839 410fb6c0 }
            // n = 7, score = 100
            //   c1fa05               | lea                 eax, [0x1cfea]
            //   8bc2                 | dec                 eax
            //   c1e81f               | cmp                 ecx, eax
            //   03d0                 | je                  0x354
            //   0fbec2               | nop                 
            //   6bc839               | mov                 ecx, dword ptr [ebx]
            //   410fb6c0             | dec                 eax

        $sequence_1 = { 488b00 e9???????? 418b4e24 4803cb 420fb71459 418b4e1c 4803cb }
            // n = 7, score = 100
            //   488b00               | dec                 eax
            //   e9????????           |                     
            //   418b4e24             | lea                 ecx, [edx + 0x110]
            //   4803cb               | dec                 eax
            //   420fb71459           | mov                 ecx, dword ptr [edx + 0x20]
            //   418b4e1c             | dec                 esp
            //   4803cb               | lea                 esp, [0x19f63]

        $sequence_2 = { 4585d2 75aa 488b00 e9???????? 8b4e24 4903cb 420fb71451 }
            // n = 7, score = 100
            //   4585d2               | mov                 ecx, dword ptr [edi + 0x130]
            //   75aa                 | dec                 eax
            //   488b00               | add                 eax, ebx
            //   e9????????           |                     
            //   8b4e24               | call                eax
            //   4903cb               | dec                 ecx
            //   420fb71451           | mov                 dword ptr [edi + 0x100], eax

        $sequence_3 = { 448bc2 4183c820 3c19 410fb641ff 440f47c2 4533c2 4569d093010001 }
            // n = 7, score = 100
            //   448bc2               | inc                 ebp
            //   4183c820             | test                edx, edx
            //   3c19                 | jne                 0x1f27
            //   410fb641ff           | test                dl, dl
            //   440f47c2             | jne                 0x1f59
            //   4533c2               | inc                 ecx
            //   4569d093010001       | cmp                 ecx, 0x3b67f41a

        $sequence_4 = { e8???????? 90 4c8d942490000000 4883bc24a800000008 4c0f43942490000000 }
            // n = 5, score = 100
            //   e8????????           |                     
            //   90                   | inc                 ecx
            //   4c8d942490000000     | cmp                 byte ptr [esi + 0x9c], 0
            //   4883bc24a800000008     | pop    esi
            //   4c0f43942490000000     | pop    ebp

        $sequence_5 = { 7775 488b4918 483bc8 746c 7314 482bc5 488bd0 }
            // n = 7, score = 100
            //   7775                 | test                ebx, ebx
            //   488b4918             | dec                 eax
            //   483bc8               | arpl                word ptr [ebx + 0x3c], cx
            //   746c                 | inc                 esp
            //   7314                 | mov                 esi, dword ptr [ecx + ebx + 0x88]
            //   482bc5               | dec                 esp
            //   488bd0               | add                 esi, ebx

        $sequence_6 = { 4d8d4901 2c41 448bc2 4183c820 3c19 410fb641ff }
            // n = 6, score = 100
            //   4d8d4901             | dec                 eax
            //   2c41                 | cmp                 eax, 0x1f
            //   448bc2               | ja                  0x123e
            //   4183c820             | movzx               eax, bl
            //   3c19                 | dec                 eax
            //   410fb641ff           | sub                 eax, ecx

        $sequence_7 = { c5f92f25???????? 0f82b1000000 48c1e82c c5e9eb15???????? c5f1eb0d???????? 4c8d0d76cb0000 c5f35cca }
            // n = 7, score = 100
            //   c5f92f25????????     |                     
            //   0f82b1000000         | mov                 eax, dword ptr [ecx + eax*8]
            //   48c1e82c             | test                byte ptr [eax + edx + 0x38], 1
            //   c5e9eb15????????     |                     
            //   c5f1eb0d????????     |                     
            //   4c8d0d76cb0000       | dec                 eax
            //   c5f35cca             | lea                 ecx, [0x17a6a]

        $sequence_8 = { e8???????? 488bcd e8???????? 90 488b5318 4883fa08 }
            // n = 6, score = 100
            //   e8????????           |                     
            //   488bcd               | dec                 eax
            //   e8????????           |                     
            //   90                   | lea                 ecx, [edx + 0xf0]
            //   488b5318             | dec                 eax
            //   4883fa08             | lea                 ecx, [edx + 0x110]

        $sequence_9 = { 488b442458 488d4db0 660f6f05???????? 498bd5 458bc4 f30f7f45c0 4c8928 }
            // n = 7, score = 100
            //   488b442458           | add                 esi, ebx
            //   488d4db0             | dec                 ebp
            //   660f6f05????????     |                     
            //   498bd5               | cmp                 esi, ebx
            //   458bc4               | je                  0x269
            //   f30f7f45c0           | nop                 dword ptr [eax + eax]
            //   4c8928               | inc                 cx

    condition:
        7 of them and filesize < 464896
}
Download all Yara Rules