logo

Unpacking what's packed: DotRunPeX analysis

ID: 498eb595-3c86-5b57-97cd-d72d8029ffd6

STIX ID: report--498eb595-3c86-5b57-97cd-d72d8029ffd6

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2023-09-18

Date Updated: 2026-04-19

Author: Jarosław Jedynak

...
...

CERT analysis of a Polish-targeted malspam campaign that used a stolen corporate account to deliver a multi-stage .NET dropper (WPF-based) which unpacked a DotRunPeX/KoiVM-packed payload; dynamic debugging extracted AES keys to recover embedded AgentTesla and other stealer payloads, and the team released unpacking tooling, YARA rules and sample hashes to improve detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.