<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dnspy on bubka hacks stuff</title><link>https://hexpysya.github.io/tags/dnspy/</link><description>Recent content in Dnspy on bubka hacks stuff</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Sun, 01 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hexpysya.github.io/tags/dnspy/index.xml" rel="self" type="application/rss+xml"/><item><title>CDEF-XWorm</title><link>https://hexpysya.github.io/investigations/cdef-xworm/</link><pubDate>Sun, 01 Mar 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/cdef-xworm/</guid><description>A .NET XWorm RAT that establishes triple persistence via scheduled task, startup shortcut, and registry Run key, implements keylogging, clipboard hijacking for crypto wallets, and communicates with multiple C2 servers over TCP using AES-ECB encrypted payloads.</description></item><item><title>HTB-Bypass</title><link>https://hexpysya.github.io/investigations/htb-bypass/</link><pubDate>Wed, 28 Jan 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-bypass/</guid><description/></item><item><title>PoshC2: Sharp_v4_x64.dll</title><link>https://hexpysya.github.io/investigations/poschc2-sharp_v4_x64.dll/</link><pubDate>Tue, 25 Nov 2025 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/poschc2-sharp_v4_x64.dll/</guid><description>A .NET DLL decodes architecture-specific shellcode from an embedded base64 string, allocates executable memory, and spawns a thread to execute it. The shellcode performs NTDLL unhooking, AMSI and ETW patching before executing an embedded PE payload identified as a PoshC2 dropper.</description></item><item><title>PoshC2: Dropper-cs.exe</title><link>https://hexpysya.github.io/investigations/dropper-cs.exe-analysis/</link><pubDate>Sun, 23 Nov 2025 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/dropper-cs.exe-analysis/</guid><description>C2 .NET implant. AES-encrypted config, HTTPS beacon to &lt;code&gt;192.168.248.128&lt;/code&gt;, fileless in-memory execution, anti-debug via divide-by-zero.</description></item></channel></rss>