Tracking PavinLoader across ClickFix and fake download campaigns
ID: f569f1be-dc36-5e8e-8824-ea16cf7f3981
STIX ID: report--f569f1be-dc36-5e8e-8824-ea16cf7f3981
Feed Name: Malwarebytes Blog
This report analyzes PavinLoader, a heavily obfuscated multi-stage .NET loader observed across several campaigns (RenPy, ClickFix, fake software downloads) that uses EtherHiding (blockchain-based C2 discovery), MSBuild/.csproj/.bat abuse, and trojanized .NET DLLs to deliver payloads including Amatera Stealer; the analysis details distribution methods, stage functionality (loader, EtherHiding loader, anti-analysis DLL, PE loader), anti-analysis and obfuscation techniques, and provides IOCs (SHA-256 hashes, IPs, domains, and URLs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
