Contenido disponible en idioma original
class="post-article">

NETDropper

.NET dropper using Spanish invoice lure (Factura). Drops XZvu.exe embedded PE payload. AES encryption (TAes! reference). Entropy 7.90 maximum packing. Pure .NET binary (single import mscoree.dll). System.Drawing.Bitmap image manipulation.

Perfil de amenaza
Tipo Loader
Lenguaje de programaciónC#/.NET
Protocolo C2HTTPS
Primera detección2023
Objetivos Latin Amerika/İspanya
Propósito / Capacidades
  • Dropper
Aún no se han identificado servidores C2 para esta familia.

Informes de investigación (1)

Yüksek

NETDropper Facturaelectriccorrespo -- XZvu.exe Gomulu PE Payload, Entropi 7.90 Maksimum Paketleme, TAes AES Sifreleme Kaniti, mscoree.dll Tek Import Pure NET Binary | Yuksek

NETDropper Facturaelectriccorrespo ZIP 948KB net PE 1MB. XZvu.exe gomulu PE payload. Entropi 7.90 maksimum paketleme. TAes AES sifreleme. mscoree.dll tek import pure NET binary.

Leer informe →