logo

Peeling Back the Layers of .NET Malware

ID: e13e968e-3c61-5178-a585-aab69d4e9946

STIX ID: report--e13e968e-3c61-5178-a585-aab69d4e9946

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

This blog post analyzes an obfuscated .NET malware sample found in a startup .url that pointed to a local executable; the sample XOR-deobfuscates embedded C# code, compiles a DLL at runtime, decodes an embedded PNG resource to extract a payload, and contains capabilities to disable antivirus, steal credentials, log keystrokes, and control a webcam.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.