April 29, 2024, 1:41 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Hello Everybody! Today i will be conducting an analysis of a .NET information stealer.

MD5 hash: DC4200AC514006F084EAD7F83B84C928
Virus Total Link: VirusTotal

Analysis

File version/name information

The sample effectively disguises itself as a Data Recovery tool to bypass user detection. It is a 32-bit .NET binary, which allows for the conversion of the binary back to Intermediate Language (IL). This can be done using tools designed for such purposes, with DNSpy being a prime example.

Upon closer examination of the binary, …

analysis back binary bypass code conversion data data recovery detection effectively hash hello information information stealer intermediate language link malware analysis md5 name recovery sample stealer today tool version

Sr. Product Manager

@ MixMode | Remote, US

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

PNT/NAVWAR Space Electronic Warfare Instructor II – Officer Training Course

@ Aleut Federal | Colorado Springs, Colorado, United States

Sr Director, Cybersecurity SIRT

@ Workday | USA, VA, McLean