{"id":"3ef62083dc7fcdcad082954d8675b3de","title":".NET凭据窃取器+Keylogger — .NET凭据窃取器+Keylogger · 木马/恶意软件 · PE32 .NET","md5":"3ef62083dc7fcdcad082954d8675b3de","sha256":"4d08acae8180270235f519d9ec24e27e94c32f5c0370edd122bc6dc1f33a8240","family":".NET凭据窃取器+Keylogger","apt":null,"verdict":null,"sample_type":"木马/恶意软件","lang":"C#","file_format":"PE32 .NET","compiler":"VB.NET","published_at":"2026-08-04T16:00:00.000Z","summary":"该样本是一个.NET 信息窃取器 (Infostealer) + RAT，使用 VB.NET 编译，大小 239.5 KB。 核心能力: 凭据窃取(多协议): Password + DomainPassword + FtpPassword — 密码/域/FTP凭据全覆盖 网络凭据: CredentialCache + NetworkCredential — Windows凭据管理器窃取 键盘记录: KeyloggerInterval — 可配置的键盘输入捕获 屏幕捕获: ScreenInterval + CopyFromScreen + PrimaryScreen — 远程桌面监控 HTTP C2: HttpWebResponse + PublicIpAddressGrab — HTTP协议 + 公网IP定位 注册表持久化: StartupRegName + StartupInstallationName + StartupDirectoryPath — 多重自启动 C2配置: hostmask + hoster + Host — 多C2地址配置 SHA256: 4d08acae8180270235f519d9ec24e27e94c32f5c0370edd122bc6dc1f33a8240","url":"https://zseceye.com/report/3ef62083dc7fcdcad082954d8675b3de","json_url":"https://zseceye.com/report/3ef62083dc7fcdcad082954d8675b3de.json","html_url":"https://zseceye.com/report/3ef62083dc7fcdcad082954d8675b3de","hash_urls":{"md5":"https://zseceye.com/hash/3ef62083dc7fcdcad082954d8675b3de","sha256":"https://zseceye.com/hash/4d08acae8180270235f519d9ec24e27e94c32f5c0370edd122bc6dc1f33a8240"},"search_urls":{"md5":"https://zseceye.com/?q=3ef62083dc7fcdcad082954d8675b3de","sha256":"https://zseceye.com/?q=4d08acae8180270235f519d9ec24e27e94c32f5c0370edd122bc6dc1f33a8240"},"sample_download_url":"https://zseceye.com/report/3ef62083dc7fcdcad082954d8675b3de/sample","sample_filename":"4d08acae.zip","iocs":[],"ips":[]}