April 29, 2024, 1:41 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Hello Everybody! Today i will be conducting an analysis of a .NET information stealer.

MD5 hash: DC4200AC514006F084EAD7F83B84C928
Virus Total Link: VirusTotal

Analysis

File version/name information

The sample effectively disguises itself as a Data Recovery tool to bypass user detection. It is a 32-bit .NET binary, which allows for the conversion of the binary back to Intermediate Language (IL). This can be done using tools designed for such purposes, with DNSpy being a prime example.

Upon closer examination of the binary, …

analysis back binary bypass code conversion data data recovery detection effectively hash hello information information stealer intermediate language link malware analysis md5 name recovery sample stealer today tool version

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Security Operations Manager-West Coast

@ The Walt Disney Company | USA - CA - 2500 Broadway Street

Vulnerability Analyst - Remote (WFH)

@ Cognitive Medical Systems | Phoenix, AZ, US | Oak Ridge, TN, US | Austin, TX, US | Oregon, US | Austin, TX, US

Senior Mainframe Security Administrator

@ Danske Bank | Copenhagen V, Denmark