Blog | G5 Cyber Security

Reversing Multilayer .NET Malware

A malware sample has been traversing the Internet disguised as an image of a woman. The malware sample uses several layers of obfuscation to hide its payload, including the use of steganography. Steganography is used to decrypt and execute a second dropper, which in turn installs a user-land rootkit to further hide its intentions. The rootkit adds another layer of obfuscated obfuscation by installing a DarkComet backdoor, using RC4 encryption to encrypt its configuration settings and send data to its command and control server.”]

Source: https://blog.talosintelligence.com/2014/11/reversing-multilayer-net-malware.html

Exit mobile version