typeentityconfidencemediumcreated2026-07-26updated2026-07-26dotnetmalware-familyloaderobfuscationpayloadcode-injectiondefense-evasionrijndaelmd5

unclassified-dotnet-rijndael-md5-resource-loader

Overview

A commodity .NET Framework crypter/loader family distinguished by its use of RijndaelManaged symmetric encryption with an MD5CryptoServiceProvider-derived key, layered with CryptoStream and GZipStream decompression, and reflective loading via DynamicMethod / ILGenerator. Outer binary masquerades as a generic Windows GUI executable. Payload is embedded in the high-entropy .text section rather than a traditional named resource. Two confirmed siblings (38582041, dc45393f).

Build Stack

  • Language: C# / .NET Framework PE32 (Mono/.NET assembly) ^[sample 38582041/file.txt]
  • Compiler: MSVC linker v48.0 (Visual Studio 2019+) ^[sample 38582041/pefile.txt]
  • Obfuscator: Likely ConfuserEx or derivative — obfuscated namespace identifiers (Ovjqupoaptm.Properties, Puxotm.exe) and high-entropy .text section ^[sample 38582041/strings.txt]
  • Packer: None native — remains valid .NET assembly
  • Signing: Unsigned
  • Timestamp: Fabricated future date (Dec 2050) ^[sample 38582041/rabin2-info.txt]

Deploy / TTPs

MITRE ATT&CK Technique Evidence
T1027 Obfuscated Files or Information RijndaelManaged + CryptoStream + GZipStream layered encryption ^[sample 38582041/capa.txt]
T1140 Deobfuscate/Decode Files or Information FromBase64String → MD5-derived key → CreateDecryptor → GZipStream decompress ^[sample 38582041/strings.txt]
T1560.002 Archive Collected Data::Archive via Library GZipStream decompression of payload ^[sample 38582041/capa.txt]
T1129 Shared Modules LoadLibrary + GetProcAddress P/Invoke for runtime API resolution ^[sample 38582041/strings.txt]
T1620 Reflective Code Loading DynamicMethod + ILGenerator + GetDelegateForFunctionPointer reflective assembly loading ^[sample 38582041/capa.txt]
T1055 Process Injection (inferred) nativeEntry / nativeSizeOfCode suggest unmanaged code injection ^[sample 38582041/strings.txt]

Variants / Aliases

  • Puxotm.exe (internal name) ^[sample 38582041/strings.txt]
  • Ovjqupoaptm.exe (secondary internal name) ^[sample 38582041/pefile.txt]

Notable Analyses

  • /intel/analyses/38582041b3f7cc4e17afab411b38cde8d1d434a030a95cca2cc644c43fe8c1b6.html — Deep static analysis of SHA-256 38582041... (RijndaelManaged + MD5CryptoServiceProvider + CryptoStream + GZipStream, Puxotm.exe / Ovjqupoaptm obfuscated identifiers, nativeEntry / nativeSizeOfCode unmanaged bridging).

Capabilities

  • rijndael-md5-derived-key-decryption
  • cryptostream-gzipstream-layered-decompression
  • manifest-resource-stream-extraction
  • dynamicmethod-ilgenerator-reflective-loading
  • runtime-api-resolution-via-pinvoke
  • nativeentry-nativesizeofcode-unmanaged-bridging
  • text-section-encrypted-payload-embedding
  • caesar-cipher-namespace-obfuscation
  • future-timestamp-anti-clustering
  • no-amsi-bypass

Related Pages