Analyse, hunt and classify malware using .NET metadata
ID: 687b84af-3213-5874-9595-ddf68bb84cdf
STIX ID: report--687b84af-3213-5874-9595-ddf68bb84cdf
Feed Name: Blaze's Security Blog
This report presents a methodology and tooling for hunting and classifying .NET malware using metadata-based identifiers (Typelib GUID and MVID), demonstrating YARA rules (via the dotnet and console modules) and a Python script to extract and analyze assembly metadata at scale. Applying this approach to families including PureCrypter/Pure*, Agent Tesla, RedLine, Quasar, and AsyncRAT, it shows how GUIDs and assembly names can cluster samples, inform high-confidence YARA detections, and surface potential crypters (e.g., “Cronos-Crypter”), while noting caveats like spoofed/empty GUIDs and obfuscation effects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
