typeanalysisfamilyunclassified-dotnet-rijndael-md5-resource-loaderconfidencemediumcreated2026-07-26updated2026-07-26
SHA-256: 38582041b3f7cc4e17afab411b38cde8d1d434a030a95cca2cc644c43fe8c1b6

SHA-256: 38582041b3f7cc4e17afab411b38cde8d1d434a030a95cca2cc644c43fe8c1b6

Filename: 4e54ab1bcda9a1e6a28c10a29ad4c3b5.exe Family (this analysis): unclassified-dotnet-rijndael-md5-resource-loader Confidence: Medium — distinct crypto primitive and obfuscation pattern from existing AES and TripleDES loader families, but commodity builder lineage is unclear.


1. Build / RE

Language / Runtime: C# / .NET Framework PE32 (Mono/.NET assembly) ^[file.txt] ^[rabin2-info.txt:1-3].

Toolchain: MSVC linker v48.0 (Visual Studio 2019+ toolchain) ^[pefile.txt:45] ^[exiftool.json:18]. Compiled to CIL with System.Reflection and System.Reflection.Emit present ^[strings.txt:29,348].

Timestamp: Fabricated — Mon Dec 19 22:31:19 2050 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]. Future-dated compilation stamps are common in obfuscated .NET binaries to break chronological clustering.

Signing: Unsigned. No certificate directory ^[rabin2-info.txt:27] ^[pefile.txt:152-154].

Sections: Standard 3-section PE: .text (entropy 7.84), .rsrc (entropy 3.96), .reloc (entropy 0.10) ^[pefile.txt:78-136]. .text size ~529 KB, high entropy consistent with encrypted payload or obfuscated CIL.

Packing / Obfuscation: No native packer. High-entropy .text (7.84) and obfuscated CIL namespace identifiers (Ovjqupoaptm.Properties, Puxotm.exe) suggest ConfuserEx or a derivative .NET obfuscator ^[strings.txt:18,43,61]. No anti-VM or anti-debug strings observed.

Embedded Resources: .rsrc is only 0x570 bytes — contains only VS_VERSIONINFO and RT_MANIFEST XML ^[pefile.txt:259-328]. The encrypted payload is therefore embedded directly in the high-entropy .text section or as a raw CIL byte array, not as a traditional named resource.

Notable API Surface:

  • RijndaelManaged + MD5CryptoServiceProvider + CryptoStream + GZipStream + FromBase64String — layered decryption and decompression pipeline ^[strings.txt:188,197,324,331,407,449] ^[capa.txt].
  • GetManifestResourceStream / GetManifestResourceNames — resource enumeration and extraction ^[strings.txt:352,531].
  • DynamicMethod + ILGenerator + GetDelegateForFunctionPointer — runtime thunk generation for reflective code loading ^[strings.txt:347-349,376,429] ^[capa.txt].
  • LoadLibrary + GetProcAddress — P/Invoke runtime API resolution ^[strings.txt:423,426].
  • nativeEntry / nativeSizeOfCode — fields indicating unmanaged native shellcode or DLL bridging ^[strings.txt:494-495].

2. Deploy / ATT&CK

Tactic Technique Evidence
DEFENSE EVASION T1027 — Obfuscated Files or Information RijndaelManaged + CryptoStream + GZipStream layered encryption ^[capa.txt] ^[strings.txt:188,197,324,331]
DEFENSE EVASION T1140 — Deobfuscate/Decode Files or Information FromBase64String → MD5-derived key → CreateDecryptor → GZipStream decompress ^[strings.txt:407,449,188,197]
COLLECTION T1560.002 — Archive Collected Data::Archive via Library GZipStream decompression of payload ^[capa.txt]
EXECUTION T1129 — Shared Modules LoadLibrary + GetProcAddress P/Invoke for runtime API resolution ^[strings.txt:423,426]
DEFENSE EVASION T1620 — Reflective Code Loading DynamicMethod + ILGenerator + GetDelegateForFunctionPointer reflective assembly loading ^[capa.txt] ^[strings.txt:347-349,429]
DEFENSE EVASION T1055 — Process Injection (inferred) nativeEntry / nativeSizeOfCode suggest unmanaged code injection into self or remote process ^[strings.txt:494-495]

Persistence: None observed statically. No registry, scheduled task, or startup-folder strings.

C2 / Comms: None observed. No hardcoded URLs, IPs, or Telegram/Discord webhooks in strings.

Attribution: Unattributed commodity crypter/loader. The Ovjqupoaptm / Puxotm namespace identifiers appear to be Caesar-cipher obfuscation of simple English words (consistent with trivial substitution obfuscation rather than ConfuserEx's random alphanumeric mangling). No overlap with known families in the corpus by method names, AMSI bypass signatures, or C2 infrastructure. Absence of AMSI bypass strings distinguishes this sample from the unclassified-dotnet-crypter-loader AES+GZip cluster.

Dynamic ground truth: CAPE skipped — no Windows guest available ^[dynamic-analysis.md]. All TTPs inferred from static evidence above.