• 52pojie Build Provenance `52pojie` (吾爱破解, "I Love Cracking") is a prominent Chinese reverse-engineering and software-cracking forum. Malware samples with PDB paths or build artefacts referencing `52pojie` may indicate:
  • AES-Managed Overlay Decryption A payload-staging pattern in which a .NET binary carries its encrypted payload not in a manifest resource, but as a raw **file overlay** appended after the last PE section. The outer binary opens its
  • AgentTesla .NET Infostealer AgentTesla is a commodity .NET Framework information stealer sold as malware-as-a-service. It targets browser credentials, clipboard data, keystrokes, screenshots, and email client credentials, exfilt
  • AutoIt Compiled Script Dropper Malware delivered as a compiled AutoIt3 script (`.a3x` or `.exe` output from AutoIt compiler). The script is executed by the AutoIt3 interpreter, providing a Turing-complete scripting environment with
  • Bitmap Steganography Payload Delivery Cross-family concept for malware that hides executable payloads inside seemingly benign image resources embedded in the PE file. The outer binary appears to be a normal .NET application with embedded
  • Browser Credential Harvesting Cross-family technique: malware reads browser credential databases from local disk to extract saved passwords, cookies, and autofill data. Targets vary by family but commonly include Chromium-based br
  • cjk-unicode-steganography CJK Unicode steganography is a custom payload-hiding technique in which raw binary data (typically a PE or shellcode) is encoded as a string of CJK Unified Ideograph characters. Because these characte
  • clipboard-hijack-cryptocurrency — Replacing copied wallet addresses with attacker-controlled ones Malware monitors the Windows clipboard for strings that match cryptocurrency address patterns. When the user copies an address (e.g., to send funds), the malware immediately replaces it in the clipboa
  • debug-build-capa-false-positives Recurring false-positive pattern in Mandiant capa static analysis when targeting .NET Framework binaries compiled in **Debug** configuration. The presence of compiler-generated attributes that are har
  • .NET Manifest Resource Decryption A common payload-staging pattern in .NET malware where the encrypted or compressed payload is embedded as a `Resource` (`.rsrc` / `ManifestResource`) inside the assembly metadata. At runtime, the load
  • double-extension-masquerade A Windows-specific social-engineering technique where a PE executable is given a filename ending in a benign extension followed by the real `.exe` extension, e.g. `Invoice.pdf.exe`. Because Windows Ex
  • Email Client Credential Theft Cross-family technique: malware extracts saved credentials, account settings, and mail stores from local email client applications. Targets vary by family but commonly include Outlook, Thunderbird, Fo
  • Encrypted RCData Resource Configuration Staging Malware stores its operational configuration (C2 endpoints, mutex names, persistence paths, feature flags) inside a PE resource of type `RT_RCDATA` rather than in the `.data` section. The blob is typi
  • Embedded SHA256 Integrity Hash A hardcoded 64-character hexadecimal string appearing inside a binary's metadata (often the .NET `#Strings` stream or PE `.rsrc` section) that looks like a SHA-256 hash but whose purpose is not immedi
  • Fabricated Certificate Masquerade Malware authors generate self-signed code-signing certificates with Subject/Issuer Common Names borrowed from legitimate open-source or commercial software projects. Unlike [[stolen-certificate-signin
  • FTP Exfiltration Cross-family exfiltration technique: malware uploads stolen data to an attacker-controlled FTP server. Less common than SMTP or Telegram exfiltration in modern crimeware, but still observed in older f
  • Go Fake Source-Path Masquerade Anti-analysis technique in which a Go-compiled binary embeds fake vendor source paths in its program counter / line number table (`pclntab`), misleading analysts into attributing the binary to a legit
  • golang-stealer-build-pattern Recurring build artefacts observed across Go-based infostealer families (ACR Stealer, Lumma, XenoRAT).
  • IExpress SFX Dropper The Microsoft IExpress/Wextract self-extractor (`wextract.exe`) repurposed as a malware dropper. The outer PE is a legitimate Windows system binary that extracts an embedded Cabinet archive to a temp
  • image-steganography-payload-delivery Malware technique: hide executable payloads inside seemingly benign image files (JPG, PNG, BMP) or text files using plaintext markers. The carrier file is hosted on free or legitimate services (Bitbuc
  • inno-setup-legitimate-installer-abuse Threat actors repackage legitimate open-source installer frameworks (Inno Setup, NSIS, WiX) as malware droppers. The outer binary is benign software with a valid toolchain fingerprint; the payload is
  • javascript-obfuscator Commercial-grade JavaScript obfuscation commonly observed in malware droppers. Characterised by string-array lookup tables, control-flow flattening, dead-code injection, and hex-offset string referenc
  • Latin American Banking Trojan Concept Cross-family pattern for banking trojans targeting Latin American financial institutions, especially Brazilian banks. Characterized by PIX QR-code hijacking, screen-capture overlays, and synthetic inp
  • legitimate-library-masquerade Cross-family pattern: malware authors clone the identity metadata (copyright, product name, version info, description, company) of a real open-source or commercial library/framework to make their bina
  • Legitimate Remote Access Tool Abuse Attackers repackage, re-sign, or reconfigure legitimate remote-access software (ScreenConnect, NetSupport Manager, AnyDesk, TeamViewer) to establish persistent C2 without developing custom malware. Th
  • MessagePackLib Asynchronous RAT Protocol A .NET C2 wire-format pattern in which the client and server exchange commands and replies as MessagePack-serialized objects wrapped in an AES-256-HMAC envelope, transported over a TLS-encrypted TCP s
  • MinGW-w64 Build Artifacts Distinguishing features of binaries produced by the MinGW-w64 (Minimalist GNU for Windows) GCC toolchain.
  • natural-language-payload-encoding The use of human-readable prose, poetry, or dialogue as a carrier for machine-executable payloads. Instead of encoding binary data as base64, hex, or URL-safe strings, the malware author maps byte val
  • netsupport-manager-abuse NetSupport Manager is a legitimate commercial remote-access and classroom-management tool. Threat actors abuse its client installer by bundling it inside masqueraded installers (Inno Setup, IExpress,
  • Packer Identification General techniques for identifying executable packers, crypters, and protectors in static analysis.
  • PIX QR Code Fraud Cross-family concept for banking trojans that hijack Brazil's PIX instant-payment system by generating attacker-controlled QR codes.
  • PyArmor Obfuscation PyArmor is a Python obfuscation and licensing toolkit that encrypts Python source code or bytecode and decrypts it at runtime via a compiled C extension (`pyarmor_runtime.pyd`). It is commonly abused
  • PyInstaller Bootloader A small C or Win32 PE executable produced by `PyInstaller --onefile`. At runtime it:
  • Python-Packed Payload Malware whose executable logic is written in Python, then distributed inside a PE via PyInstaller, py2exe, or cx_Freeze. The outer PE is a benign-language bootloader; the threat logic lives in compile
  • Ransomware Malware family category that encrypts victim files and demands payment (typically cryptocurrency) for decryption. Often combines symmetric encryption (AES) for files with asymmetric encryption (RSA) f
  • rat — Remote-Access Trojan malware family category A **remote-access trojan (RAT)** is malware that establishes persistent, interactive control over a compromised host, giving the operator the same capabilities as a legitimate remote-administration to
  • Raw .NET Metadata Staging A staging technique where a .NET Framework assembly is stored inside another executable not as a complete PE file, but as raw Common Intermediate Language (CIL) bytecode and .NET metadata streams stri
  • Raw TCP C2 Socket Malware that uses the Berkeley sockets API directly (`WSOCK32.dll` or `ws2_32.dll`) for command-and-control communication without an application-layer framing protocol such as HTTP, HTTPS, or DNS. Thi
  • Reflective PE Loader A position-independent shellcode routine that receives a raw PE file in memory and manually maps it, resolves imports, applies relocations, and transfers execution — all without calling `LoadLibrary`
  • Rentry / Pastebin Payload Staging Abuse of text-hosting / paste services (`rentry.co`, `pastebin.com`, `paste.ee`, etc.) as a payload staging layer. Malware authors store obfuscated or partially-obfuscated VBS/BAT/PowerShell snippets
  • RWX Section Self-Modifying Code A PE section marked simultaneously readable, writable, and executable (`IMAGE_SCN_MEM_READ | IMAGE_SCN_MEM_WRITE | IMAGE_SCN_MEM_EXECUTE`, characteristics `0xE0000020`). Legitimate software rarely nee
  • SMTP Exfiltration Cross-family exfiltration technique: malware sends stolen data as email attachments or body text via hardcoded SMTP credentials. No dedicated C2 infrastructure required — the attacker only needs a dis
  • social-engineering-filename-lure The practice of naming a malicious file with a theme that exploits the victim's professional context or urgency — invoices, payments, shipping documents, purchase orders, HR notices, IT updates — to i
  • Social Engineering — Purchase Order Masquerade A social-engineering distribution pattern in which malware is packaged with a filename implying a business document — typically `PO`, `Purchase Order`, `INQUIRY`, `QUOTE`, `RFQ`, or `SALES` — often wi
  • Stolen Certificate Signing Malware authors re-use or repurpose legitimate TLS/Authenticode certificates stolen from compromised organizations to sign their payloads. This grants the binary a veneer of trust that bypasses "unkno
  • Synthetic Input Manipulation Cross-family concept for banking trojans that use `SendInput`, `mouse_event`, `keybd_event`, or Windows hooks to inject synthetic input and manipulate online banking sessions.
  • telegram-bot-exfiltration — Using the Telegram Bot API as a malware C2 channel The Telegram Bot API (`https://api.telegram.org/bot<TOKEN>`) is used as a C2 and exfiltration channel: malware POSTs victim data (clipboard contents, screenshots, geolocation, system fingerprint) to a
  • trif32-caesar-shift-23-decoder A trivial character-shift decoder (Caesar cipher with shift=23, equivalent to ROT-23 or shift backward by 3) embedded in multiple .NET Framework educational applications and games. Named after the cla
  • UPX Compression **Ultimate Packer for eXecutables** — a free, portable executable packer using compression algorithms (NRV, UCL, LZMA, zlib) to reduce binary size. UPX is open-source and widely abused by malware auth
  • version-info-masquerade Cross-family pattern: malware authors forge Windows VERSIONINFO resource blocks to impersonate a benign software vendor, open-source project, or system component. The forged metadata (FileDescription,