MalwareBazaar Database
This page shows some basic information the YARA rule DotNet_BitmapAssemblyLoader_KWBORU_Family including corresponding malware samples.
Database Entry
| YARA Rule: | DotNet_BitmapAssemblyLoader_KWBORU_Family |
|---|---|
| Author: | ShadowOpCode |
| Description: | Detects the outer .NET loader template that reconstructs a managed assembly from bitmap RGB data and invokes it reflectively |
| Firstseen: | 2026-09-28 12:44:24 UTC |
| Lastseen: | 2026-09-29 06:05:55 UTC |
| Sightings: | 5 |
Malware Samples
The table below shows all malware samples that matching this particular YARA rule (max 1000).
| Firstseen (UTC) | SHA256 hash | Tags | Signature | Reporter |
|---|