Unidentified 115 (Nim Loader)

Malware type
loader
Profile updated
2026-07-07 15:24:58

Context

According to Walmart, this is a loader written in Nim that contains an AmsiScanBuffer patch followed by a EtwEventWrite patch and that will download/decrypt a payload via AES CFB and inject it into a hardcoded process target (e.g. explorer.exe).

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Unidentified 115 (report)
  • medium.com — Unknown Nim Loader Using Psbypassclm Cafdf0E0F5Cd (report)

External references