Skip to content

Loader

Breakthrough

There is no reference available for this family and all known samples have version 1.0.0.

Breakthrough is a Windows loader.

Background

No public reference exists for this family, and every known sample carries version 1.0.0.

The Pdb-strings within the samples hint that it may be an "exclusive" loader going by the name "breakthrough", for example C:\Users\Exclusiv\Desktop\хп-пробив\Release\build.pdb

Its communication URL parameters form a fairly distinctive combination: gate.php?hwid=<guid>&os=<OS>&build=1.0.0&cpu=8

<OS> is one of: Windows95 Windows98 WindowsMe Windows95family WindowsNT3 WindowsNT4 Windows2000 WindowsXP WindowsServer2003 WindowsNTfamily WindowsVista Windows7 Windows8 Windows10


Source: Malpedia (Fraunhofer FKIE).