Uncovering .NET Malware Obfuscated by Encryption and Virtualization
ID: ecea64d5-a4b2-5b78-ac9d-23c11d73d2a7
STIX ID: report--ecea64d5-a4b2-5b78-ac9d-23c11d73d2a7
Feed Name: Palo Alto Networks Unit 42
This report analyzes a cluster of multi-stage .NET malware that hides Stage 2 payloads in the PE overlay and uses AES encryption (CBC/ECB), KoiVM code virtualization, and .NET reflection to decrypt and execute final payloads (mostly Agent Tesla and XWorm, with one FormBook/XLoader sample). It details the three-stage attack chain (overlay-encrypted Stage 1, virtualized Stage 2, decrypted Stage 3), highlights AMSI bypass tokens and in-memory execution techniques, provides IoCs (SHA-256 hashes, C2 endpoints, SMTP credentials) and recommends detection/mitigation approaches including debugger-based analysis and Palo Alto Networks protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
