data:image/s3,"s3://crabby-images/3c6c4/3c6c4361ace2b612ea097d4d041819ba3cc342ae" alt="Statically unpacking a simple .NET dropper"
Statically unpacking a simple .NET dropper
Our target is a 2-layers .NET dropper using multiple cipher passes (XOR, AES ECB and AES CBC + PBKDF2) to finally drop a Loki sample. Without even starting a debugger, we will show how to unpack it 100% statically using Malcat's builtin transformations and the python scripting engine.
Read more →