In this Twitch stream we analyze the multi-stage delivery chain used to install Jupyter / Solarmarker InfoStealer. The delivery chain includes an Inno Installer, malicious Pascal script, malicious PowerShell script, and a reflectively loaded .NET assembly.
Instead of attempting to maually decode the PowerShell we can take advantage of the fact that it relfectivly loads a .NET assembly to simply dump the assembly out of the process.
Packed sample: ee904ce81c66b774897f93b0301e297a9137295516d57ba1c4e078a383cbce39
The sample is too large to upload to Malshare directly so an encrypted zip with the password infected was uploaded instead. The sample can be downloaded from Malshare HERE.
Lab-Notes: GitHub - JupyterStealer
OALABS
2023-06-19 21:27:58 +0000 UTCm4n0w4r
2023-06-19 09:39:43 +0000 UTCOALABS
2022-02-07 23:44:39 +0000 UTCCrovax
2022-02-07 22:59:39 +0000 UTC