コンテンツは元の言語でのみ利用可能
class="post-article">

NETDropper

.NET dropper using Spanish invoice lure (Factura). Drops XZvu.exe embedded PE payload. AES encryption (TAes! reference). Entropy 7.90 maximum packing. Pure .NET binary (single import mscoree.dll). System.Drawing.Bitmap image manipulation.

脅威プロファイル
タイプ Loader
プログラミング言語C#/.NET
C2プロトコルHTTPS
初回検出2023
標的 Latin Amerika/İspanya
目的 / 機能
  • Dropper
このファミリーのC2サーバーはまだ確認されていません。

リサーチレポート (1)

Yüksek

NETDropper Facturaelectriccorrespo -- XZvu.exe Gomulu PE Payload, Entropi 7.90 Maksimum Paketleme, TAes AES Sifreleme Kaniti, mscoree.dll Tek Import Pure NET Binary | Yuksek

NETDropper Facturaelectriccorrespo ZIP 948KB net PE 1MB. XZvu.exe gomulu PE payload. Entropi 7.90 maksimum paketleme. TAes AES sifreleme. mscoree.dll tek import pure NET binary.

レポートを読む →