Live Stream VOD: AMSI Bypass Loader Part 1 (Patreon)
Content
In this Twitch stream we begin to triage a new loader that uses AMSI bypasses to avoid detection. The loader itself is .NET but as we dig deeper we discover that the AMSI bypass is implemented in PowerShell, native X64 shell code is used (no yet analyzed) and the final payload is a Async RAT.
For the first half of the stream we triage the .NET loader and PowerShell, then turn our attention to the shell code. The shell code analysis has a few tricks that might be useful for general shell code analysis... then next stream we will do full triage of the shell code.
Sample
43cc6ed0dcd1fa220283f7bbfa79aaf6342fdb5e73cdabdde67debb7e2ffc945
Notes
AMSI Bypass In The Wild - Taking a close look at this asyncrat loader with an AMSI bypass