logo

Analyse, hunt and classify malware using .NET metadata

ID: 687b84af-3213-5874-9595-ddf68bb84cdf

STIX ID: report--687b84af-3213-5874-9595-ddf68bb84cdf

Feed Name: Blaze's Security Blog

Threat Score
35/100

Date Published: 2024-03-25

Date Updated: 2026-04-19

Author: Bart

...
...

This report presents a methodology and tooling for hunting and classifying .NET malware using metadata-based identifiers (Typelib GUID and MVID), demonstrating YARA rules (via the dotnet and console modules) and a Python script to extract and analyze assembly metadata at scale. Applying this approach to families including PureCrypter/Pure*, Agent Tesla, RedLine, Quasar, and AsyncRAT, it shows how GUIDs and assembly names can cluster samples, inform high-confidence YARA detections, and surface potential crypters (e.g., “Cronos-Crypter”), while noting caveats like spoofed/empty GUIDs and obfuscation effects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.