Home Artists Posts Import Register
Patreon importer is back online! Tell your friends ✅

Content

In this Twitch stream we take a look at QVoid Stealer an open source .NET INFOSTEALER that has been dropped along with RedLine.

Set your expectations low for this one... really F-Tier stealer but we push through the cringe and write a Yara rule and a Config extractor.

Sample

ef7bb2464a2b430aa98bd65a1a40b851b57cb909ac0aea3e53729c0ff900fa42 

Notes

QVoidStealer: Lol what is up with these trash .NET stealers 

Files

Live Stream VOD: QVoidStealer .NET Cringe

This is "Live Stream VOD: QVoidStealer .NET Cringe" by OALABS on Vimeo, the home for high quality videos and the people who love them.

Comments

Karsten Hahn

The malware has typos that you corrected in the yara rule. $m5 = "AntiWebSinffers".

oalabs

Lol! Human autocorrect! Ironic given how bad my spelling is normally