BBTok Targeting Brazil: Deobfuscating the .NET Loader with dnlib and PowerShell

General News

Summary

We break down the full infection chain of the Brazilian-targeted threat BBTok and demonstrate how to deobfuscate the loader DLL using PowerShell, Python, and dnlib. Articles from Checkpoint and TrendMicro describe a similar infection chain and attribute it to BBTok banker, but to our knowledge, no one has yet published an analysis on the obfuscated .NET based loader named Trammy.dll. Figure 2: XML project file[F7] for Microsoft Build Engine containing the malicious C# code First, the freshly compiled .NET DLL[F13] opens the decoy PDF[F8] which displays a DANFE invoice to the target user. Figure 3: Stage 1—Utilizing Microsoft Build Engine to execute .NET DLLs; the letters and numbers in square brackets are references into the IoC table (click to enlarge) DANFE10103128566164.dll[F10], is not packed but obfuscated with ConfuserEx. Figure 5: Custom AppDomainManager class after removing control flow obfuscation with de4dot-cex (click to enlarge) Figure 6: Custom AppDomainManager class after de4dot-cex, string deobfuscation and indirect call elimination, the methods isAdmin and MainMalcode were manually renamed (click to enlarge) Next, Trammy.dll[F10] schedules a task that adds the folder C:\ProgramData to Windows Defender’s exclusions.

Classifications

industries
No industries detected
applications
Networking and Cloud

AskAI Classifications

Labels
No AI classifications detected

Linked Companies