内容仅以原始语言提供
class="post-article">

NETDropper

.NET dropper using Spanish invoice lure (Factura). Drops XZvu.exe embedded PE payload. AES encryption (TAes! reference). Entropy 7.90 maximum packing. Pure .NET binary (single import mscoree.dll). System.Drawing.Bitmap image manipulation.

威胁档案
类型 Loader
编程语言C#/.NET
C2协议HTTPS
首次发现2023
目标 Latin Amerika/İspanya
用途 / 能力
  • Dropper
尚未发现该家族的 C2 服务器。

研究报告 (1)

Yüksek

NETDropper Facturaelectriccorrespo -- XZvu.exe Gomulu PE Payload, Entropi 7.90 Maksimum Paketleme, TAes AES Sifreleme Kaniti, mscoree.dll Tek Import Pure NET Binary | Yuksek

NETDropper Facturaelectriccorrespo ZIP 948KB net PE 1MB. XZvu.exe gomulu PE payload. Entropi 7.90 maksimum paketleme. TAes AES sifreleme. mscoree.dll tek import pure NET binary.

阅读报告 →