원본 언어로만 콘텐츠 제공
class="post-article">

NETDropper

.NET dropper using Spanish invoice lure (Factura). Drops XZvu.exe embedded PE payload. AES encryption (TAes! reference). Entropy 7.90 maximum packing. Pure .NET binary (single import mscoree.dll). System.Drawing.Bitmap image manipulation.

위협 프로필
유형 Loader
프로그래밍 언어C#/.NET
C2 프로토콜HTTPS
첫 감지2023
대상 Latin Amerika/İspanya
목적 / 기능
  • Dropper
이 패밀리에 대해 아직 확인된 C2 서버가 없습니다.

연구 보고서 (1)

Yüksek

NETDropper Facturaelectriccorrespo -- XZvu.exe Gomulu PE Payload, Entropi 7.90 Maksimum Paketleme, TAes AES Sifreleme Kaniti, mscoree.dll Tek Import Pure NET Binary | Yuksek

NETDropper Facturaelectriccorrespo ZIP 948KB net PE 1MB. XZvu.exe gomulu PE payload. Entropi 7.90 maksimum paketleme. TAes AES sifreleme. mscoree.dll tek import pure NET binary.

보고서 읽기 →