unclassified-dotnet-rijndael-md5-resource-loader
Overview
A commodity .NET Framework crypter/loader family distinguished by its use of RijndaelManaged symmetric encryption with an MD5CryptoServiceProvider-derived key, layered with CryptoStream and GZipStream decompression, and reflective loading via DynamicMethod / ILGenerator. Outer binary masquerades as a generic Windows GUI executable. Payload is embedded in the high-entropy .text section rather than a traditional named resource. Two confirmed siblings (38582041, dc45393f).
Build Stack
- Language: C# / .NET Framework PE32 (Mono/.NET assembly) ^[sample 38582041/file.txt]
- Compiler: MSVC linker v48.0 (Visual Studio 2019+) ^[sample 38582041/pefile.txt]
- Obfuscator: Likely ConfuserEx or derivative — obfuscated namespace identifiers (
Ovjqupoaptm.Properties,Puxotm.exe) and high-entropy.textsection ^[sample 38582041/strings.txt] - Packer: None native — remains valid .NET assembly
- Signing: Unsigned
- Timestamp: Fabricated future date (Dec 2050) ^[sample 38582041/rabin2-info.txt]
Deploy / TTPs
| MITRE ATT&CK | Technique | Evidence |
|---|---|---|
| T1027 | Obfuscated Files or Information | RijndaelManaged + CryptoStream + GZipStream layered encryption ^[sample 38582041/capa.txt] |
| T1140 | Deobfuscate/Decode Files or Information | FromBase64String → MD5-derived key → CreateDecryptor → GZipStream decompress ^[sample 38582041/strings.txt] |
| T1560.002 | Archive Collected Data::Archive via Library | GZipStream decompression of payload ^[sample 38582041/capa.txt] |
| T1129 | Shared Modules | LoadLibrary + GetProcAddress P/Invoke for runtime API resolution ^[sample 38582041/strings.txt] |
| T1620 | Reflective Code Loading | DynamicMethod + ILGenerator + GetDelegateForFunctionPointer reflective assembly loading ^[sample 38582041/capa.txt] |
| T1055 | Process Injection (inferred) | nativeEntry / nativeSizeOfCode suggest unmanaged code injection ^[sample 38582041/strings.txt] |
Variants / Aliases
Puxotm.exe(internal name) ^[sample 38582041/strings.txt]Ovjqupoaptm.exe(secondary internal name) ^[sample 38582041/pefile.txt]
Notable Analyses
- /intel/analyses/38582041b3f7cc4e17afab411b38cde8d1d434a030a95cca2cc644c43fe8c1b6.html — Deep static analysis of SHA-256
38582041...(RijndaelManaged + MD5CryptoServiceProvider + CryptoStream + GZipStream,Puxotm.exe/Ovjqupoaptmobfuscated identifiers,nativeEntry/nativeSizeOfCodeunmanaged bridging).
Capabilities
rijndael-md5-derived-key-decryptioncryptostream-gzipstream-layered-decompressionmanifest-resource-stream-extractiondynamicmethod-ilgenerator-reflective-loadingruntime-api-resolution-via-pinvokenativeentry-nativesizeofcode-unmanaged-bridgingtext-section-encrypted-payload-embeddingcaesar-cipher-namespace-obfuscationfuture-timestamp-anti-clusteringno-amsi-bypass
Related Pages
- unclassified-dotnet-crypter-loader — Sister family using AES + GZip + Base64 with AMSI bypass
- unclassified-dotnet-tripledes-resource-loader — Sister family using TripleDES + Base64 resource decryption
- confuserex-obfuscation — Build/RE technique page for .NET obfuscation
- dotnet-manifest-resource-decryption — Generic concept page for .NET payload-staging patterns