SYMBOLCOMMON_NAMEaka. SYNONYMS
win.photofork (Back to overview)

PHOTOFORK

VTCollection    

PHOTOFORK is a downloader which is a modified version of GZIPLOADER. It was first detected in February 2023 and was distributed by TA581 along with an unattributed threat activity cluster that facilitated initial access. In this version, the configuration file is no longer encrypted using a simple XOR algorithm with a 64-byte key. Instead, it uses a custom algorithm previously used by the Standard core loader. This algorithm decrypts DLL strings that are needed to resolve handles to the necessary DLLs later on. The strings are decrypted using an algorithm that splits the data into DWORDs and XORs it against a random key. The main objective of PHOTOFORK remains the same as GZIPLOADER, i.e. to deliver an encrypted bot and core DLL loader (forked) that loads the Forked ICEDID bot into memory using a custom PE format.

References
2023-10-30 ⋅ Proofpoint ⋅ Axel F, Selena Larson
Security Brief: TA571 Delivers IcedID Forked Loader
PHOTOFORK TA571
2023-03-27 ⋅ Proofpoint ⋅ Joe Wise, Kelsey Merriman, Pim Trouerbach
Fork in the Ice: The New Era of IcedID
IcedID PHOTOFORK PHOTOLITE PhotoLoader
Yara Rules
[TLP:WHITE] win_photofork_auto (20260917 | Detects win.photofork.)
rule win_photofork_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.photofork."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.photofork"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4d85d2 7515 8d56fc 33c9 41b8fe6a7a69 e8???????? }
            // n = 6, score = 400
            //   4d85d2               | inc                 esp
            //   7515                 | mov                 byte ptr [ebp - 0x1c], ah
            //   8d56fc               | mov                 dword ptr [ebp - 0x18], 0x33816931
            //   33c9                 | mov                 dword ptr [ebp - 0x14], 0x37856d35
            //   41b8fe6a7a69         | mov                 dword ptr [ebp - 0x10], 0x42f26139
            //   e8????????           |                     

        $sequence_1 = { be01000000 4803f9 493bf7 0f83af000000 0f1f4000 66660f1f840000000000 885c2420 }
            // n = 7, score = 400
            //   be01000000           | jb                  0x920
            //   4803f9               | dec                 esp
            //   493bf7               | lea                 ecx, [esp + 0x24]
            //   0f83af000000         | dec                 eax
            //   0f1f4000             | lea                 edx, [esp + 0x30]
            //   66660f1f840000000000     | dec    eax
            //   885c2420             | lea                 ecx, [ebp + 0xa0]

        $sequence_2 = { 4885d2 7515 8d5005 33c9 }
            // n = 4, score = 400
            //   4885d2               | inc                 ebx
            //   7515                 | lea                 ecx, [ecx + eax]
            //   8d5005               | dec                 eax
            //   33c9                 | add                 ecx, 0x2c6

        $sequence_3 = { 4803f9 493bf7 0f83af000000 0f1f4000 }
            // n = 4, score = 400
            //   4803f9               | mov                 edi, ecx
            //   493bf7               | dec                 esp
            //   0f83af000000         | mov                 esi, edx
            //   0f1f4000             | inc                 ecx

        $sequence_4 = { 8b45b0 0fb645ac 84c0 7521 488bcb 0f1f840000000000 8b448db0 }
            // n = 7, score = 400
            //   8b45b0               | jb                  0x199b
            //   0fb645ac             | dec                 ebp
            //   84c0                 | mov                 eax, dword ptr [eax]
            //   7521                 | dec                 esp
            //   488bcb               | cmp                 eax, edx
            //   0f1f840000000000     | jne                 0x197b
            //   8b448db0             | xor                 eax, eax

        $sequence_5 = { 488d55e8 498bcc e8???????? 4c8bbc2498000000 }
            // n = 4, score = 400
            //   488d55e8             | dec                 eax
            //   498bcc               | mov                 dword ptr [ecx], eax
            //   e8????????           |                     
            //   4c8bbc2498000000     | dec                 eax

        $sequence_6 = { 4d85d2 7515 8d56fc 33c9 41b8fe6a7a69 }
            // n = 5, score = 400
            //   4d85d2               | mov                 byte ptr [esp + 0x58], bl
            //   7515                 | mov                 dword ptr [esp + 0x5c], 0x561b69a8
            //   8d56fc               | mov                 dword ptr [esp + 0x60], 0x561d69a8
            //   33c9                 | dec                 eax
            //   41b8fe6a7a69         | cmp                 ecx, 4

        $sequence_7 = { 4533e4 498bf0 4c8bf9 418bdc 6685c0 741d 4c8bc9 }
            // n = 7, score = 400
            //   4533e4               | xor                 eax, 0x4f50b987
            //   498bf0               | mov                 dword ptr [ebp + ecx*4 - 0x15], eax
            //   4c8bf9               | dec                 eax
            //   418bdc               | inc                 ecx
            //   6685c0               | dec                 eax
            //   741d                 | cmp                 ecx, 3
            //   4c8bc9               | jb                  0x16f5

        $sequence_8 = { 488bf8 4885c0 758a e9???????? 85c0 }
            // n = 5, score = 400
            //   488bf8               | dec                 eax
            //   4885c0               | lea                 ebp, [esp - 0x1c0]
            //   758a                 | dec                 eax
            //   e9????????           |                     
            //   85c0                 | sub                 esp, 0x2c0

        $sequence_9 = { 8d5301 33c9 41b85f70353a e8???????? 4c8bc8 }
            // n = 5, score = 400
            //   8d5301               | dec                 ecx
            //   33c9                 | sub                 edi, 1
            //   41b85f70353a         | jne                 0x1317
            //   e8????????           |                     
            //   4c8bc8               | xor                 edx, edx

    condition:
        7 of them and filesize < 99328
}
Download all Yara Rules