SYMBOLCOMMON_NAMEaka. SYNONYMS
win.photolite (Back to overview)

PHOTOLITE

VTCollection    

PHOTOLITE is the lite version of the GZIPLOADER with limited capabilities i.e. for example it does not have any functionality to exfiltrate the host information. This new variant is observed as a follow-on payload in a TA542 Emotet campaign back in November'22. contains a static URL to download a "Bot Pack" file with a static name (botpack.dat) which results in the IcedID Lite DLL Loader, and then delivers the Forked version of IcedID Bot, leaving out the webinjects and backconnect functionality that would typically be used for banking fraud.

References
2023-03-27 ⋅ Proofpoint ⋅ Joe Wise, Kelsey Merriman, Pim Trouerbach
Fork in the Ice: The New Era of IcedID
IcedID PHOTOFORK PHOTOLITE PhotoLoader
2023-01-09 ⋅ Intrinsec ⋅ CTI Intrinsec, Intrinsec
Emotet returns and deploys loaders
BumbleBee Emotet IcedID PHOTOLITE
2022-11-16 ⋅ Proofpoint ⋅ Axel F, Pim Trouerbach
A Comprehensive Look at Emotet Virus’ Fall 2022 Return
BumbleBee Emotet PHOTOLITE
Yara Rules
[TLP:WHITE] win_photolite_auto (20260917 | Detects win.photolite.)
rule win_photolite_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.photolite."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.photolite"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { c78588050000b7196945 8b8578050000 8a8574050000 84c0 751f 488bcb }
            // n = 6, score = 400
            //   c78588050000b7196945     | mov    ecx, ebx
            //   8b8578050000         | mov                 eax, dword ptr [ebp + ecx*4 + 0x44c]
            //   8a8574050000         | xor                 eax, edx
            //   84c0                 | test                al, al
            //   751f                 | jne                 0x1f
            //   488bcb               | dec                 eax

        $sequence_1 = { 493bce 72eb 488d9578050000 488d4d40 e8???????? }
            // n = 5, score = 400
            //   493bce               | dec                 eax
            //   72eb                 | mov                 ecx, ebx
            //   488d9578050000       | mov                 eax, dword ptr [ebp + ecx*4 + 0x3ac]
            //   488d4d40             | xor                 eax, edx
            //   e8????????           |                     

        $sequence_2 = { 8a85a8030000 84c0 751b 488bcb 8b848dac030000 33c2 }
            // n = 6, score = 400
            //   8a85a8030000         | mov                 edx, edi
            //   84c0                 | dec                 eax
            //   751b                 | lea                 eax, [ebx + 0x6a]
            //   488bcb               | mov                 al, byte ptr [ebp + 0x3a8]
            //   8b848dac030000       | test                al, al
            //   33c2                 | jne                 0x1f

        $sequence_3 = { 8b854c040000 8a8548040000 84c0 751b 488bcb 8b848d4c040000 33c2 }
            // n = 7, score = 400
            //   8b854c040000         | dec                 ecx
            //   8a8548040000         | cmp                 ecx, esi
            //   84c0                 | jb                  0xfffffff0
            //   751b                 | dec                 eax
            //   488bcb               | lea                 edx, [ebp + 0x578]
            //   8b848d4c040000       | dec                 eax
            //   33c2                 | lea                 ecx, [ebp + 0x40]

        $sequence_4 = { e8???????? 488905???????? 889d64010000 c7856801000027c05167 c7856c01000004c45552 c7857001000005d7566f c785740100000ec34a26 }
            // n = 7, score = 400
            //   e8????????           |                     
            //   488905????????       |                     
            //   889d64010000         | mov                 al, byte ptr [ebp + 0x574]
            //   c7856801000027c05167     | test    al, al
            //   c7856c01000004c45552     | jne    0x29
            //   c7857001000005d7566f     | dec    eax
            //   c785740100000ec34a26     | mov    ecx, ebx

        $sequence_5 = { 48c1e220 480bc2 4f8d0480 33d2 41f7f3 }
            // n = 5, score = 400
            //   48c1e220             | mov                 ecx, ebx
            //   480bc2               | mov                 eax, dword ptr [ebp + ecx*4 + 0x2d0]
            //   4f8d0480             | xor                 eax, edx
            //   33d2                 | mov                 dword ptr [ebp + 0x588], 0x456919b7
            //   41f7f3               | mov                 eax, dword ptr [ebp + 0x578]

        $sequence_6 = { 498be3 5d c3 48895c2408 57 4881ec30020000 33db }
            // n = 7, score = 400
            //   498be3               | dec                 edi
            //   5d                   | lea                 eax, [eax + eax*4]
            //   c3                   | xor                 edx, edx
            //   48895c2408           | inc                 ecx
            //   57                   | div                 ebx
            //   4881ec30020000       | mov                 byte ptr [ebp + 0x164], bl
            //   33db                 | mov                 dword ptr [ebp + 0x168], 0x6751c027

        $sequence_7 = { ff15???????? 8a4301 488d4c2472 88442471 498bd7 488d436a }
            // n = 6, score = 400
            //   ff15????????         |                     
            //   8a4301               | mov                 al, byte ptr [ebx + 1]
            //   488d4c2472           | dec                 eax
            //   88442471             | lea                 ecx, [esp + 0x72]
            //   498bd7               | mov                 byte ptr [esp + 0x71], al
            //   488d436a             | dec                 ecx

        $sequence_8 = { e8???????? 488905???????? 885d08 c7450cdc739a67 }
            // n = 4, score = 100
            //   e8????????           |                     
            //   488905????????       |                     
            //   885d08               | sub                 esp, 0x230
            //   c7450cdc739a67       | xor                 ebx, ebx

        $sequence_9 = { ffd0 b840000000 488d4c2450 0f1f4000 c60100 }
            // n = 5, score = 100
            //   ffd0                 | dec                 eax
            //   b840000000           | lea                 edx, [esp + 0x20]
            //   488d4c2450           | dec                 eax
            //   0f1f4000             | lea                 ecx, [esp + 0x30]
            //   c60100               | jne                 0x25

        $sequence_10 = { 7523 ba01000000 33c9 41b8a1875547 e8???????? }
            // n = 5, score = 100
            //   7523                 | dec                 eax
            //   ba01000000           | mov                 dword ptr [esp + 8], ebx
            //   33c9                 | push                edi
            //   41b8a1875547         | dec                 eax
            //   e8????????           |                     

        $sequence_11 = { 72ea 4c8d4c2458 4c8bc7 488d542424 488d8dc0000000 }
            // n = 5, score = 100
            //   72ea                 | mov                 edx, 1
            //   4c8d4c2458           | xor                 ecx, ecx
            //   4c8bc7               | inc                 ecx
            //   488d542424           | mov                 eax, 0x475587a1
            //   488d8dc0000000       | mov                 byte ptr [ebp + 8], bl

        $sequence_12 = { 41b89e6c7cec e8???????? 4c8bc0 488b05???????? 4c898020110000 488d542420 488d4c2430 }
            // n = 7, score = 100
            //   41b89e6c7cec         | mov                 eax, dword ptr [ebp + ecx*4 + 0x190]
            //   e8????????           |                     
            //   4c8bc0               | dec                 ecx
            //   488b05????????       |                     
            //   4c898020110000       | mov                 esp, ebx
            //   488d542420           | pop                 ebp
            //   488d4c2430           | ret                 

        $sequence_13 = { c745e80445c571 c745ec0e45c571 c745f00445f571 8b45cc 0fb645c8 84c0 }
            // n = 6, score = 100
            //   c745e80445c571       | jmp                 0xd
            //   c745ec0e45c571       | mov                 edx, 1
            //   c745f00445f571       | mov                 byte ptr [ebp - 0x20], bl
            //   8b45cc               | mov                 dword ptr [ebp - 0x1c], 0x1d10b22d
            //   0fb645c8             | mov                 dword ptr [ebp - 0x18], 0x4151bb23
            //   84c0                 | mov                 dword ptr [ebp - 0x14], 0x1f0eb368

        $sequence_14 = { 443b44242c 0f94c3 8bc3 4881c480000000 5b c3 33c0 }
            // n = 7, score = 100
            //   443b44242c           | mov                 dword ptr [ebp - 0x10], 0x7362d746
            //   0f94c3               | inc                 ecx
            //   8bc3                 | mov                 eax, 0xec7c6c9e
            //   4881c480000000       | dec                 esp
            //   5b                   | mov                 eax, eax
            //   c3                   | dec                 esp
            //   33c0                 | mov                 dword ptr [eax + 0x1120], eax

        $sequence_15 = { 885de0 c745e42db2101d c745e823bb5141 c745ec68b30e1f c745f046d76273 }
            // n = 5, score = 100
            //   885de0               | mov                 dword ptr [ebp + 0x174], 0x264ac30e
            //   c745e42db2101d       | test                al, al
            //   c745e823bb5141       | jne                 0x1f
            //   c745ec68b30e1f       | dec                 eax
            //   c745f046d76273       | mov                 ecx, ebx

    condition:
        7 of them and filesize < 99328
}
Download all Yara Rules