HTTP(S) uploader
- First seen
- 2019-08-15 00:00:00
- Malware type
- spyware
- Profile updated
- 2026-07-07 14:49:50
Targeted industries: government-and-public-sector financial-services
Context
The HTTP(S) uploader is a Lazarus tool responsible for data exfiltration, by using the HTTP or HTTPS protocols. It accepts up to 10 command line parameters: a 29-byte decryption key, a C&C for data exfiltration, the name of a local RAR split volume, the name of the multivolume archive on the server side, the size of a RAR split (max 200,000 kB), the starting index of a split, the ending index of a split, and the switch -p with a proxy IP address and port
Reports & references
- ESET — Amazon Themed Campaigns Lazarus Netherlands Belgium (report)
- hvs-consulting.de — Threatreport Lazarus (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Httpsuploader (report)
- Kaspersky — 100803 (report)