<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="margin:0px;font-size:12pt;background-color:rgb(255, 255, 255)"><span style="margin:0px"><span style="margin:0px;color:rgb(0, 0, 0) !important;background-color:rgb(255, 255, 255)"><span style="margin:0px;background-color:rgb(255, 255, 255) !important"><span style="margin:0px;background-color:rgb(255, 255, 255) !important"><span style="margin:0px;background-color:rgb(255, 255, 255) !important"><span style="margin:0px;font-size:14.67px">Hello,</span></span></span></span></span></span></span>
<div style="margin:0px;font-size:12pt;background-color:rgb(255, 255, 255)">
<div style="margin:0px">
<div style="margin:0px;color:rgb(0, 0, 0) !important;background-color:rgb(255, 255, 255)">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;font-size:12pt;color:rgb(0, 0, 0) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;font-size:12pt;color:rgb(0, 0, 0) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;font-size:12pt;color:rgb(0, 0, 0) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;font-size:12pt;color:rgb(0, 0, 0) !important">
<div style="margin:0px;background-color:rgb(255, 255, 255) !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important"><span style="margin:0px;background-color:white !important"></span>
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important"><span style="margin:0px;background-color:white !important"></span>
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:15px;color:rgb(32, 31, 30) !important;background-color:white !important">
<div style="margin:0px;font-size:12pt;color:black !important"><span style="margin:0px;background-color:white !important"></span>
<div style="margin:0px;background-color:white !important">
<div style="margin:0px;font-size:14.67px;background-color:white !important">I hope everyone is doing well!</div>
<div style="margin:0px;font-size:14.67px;background-color:white !important"><br>
</div>
<div style="margin:0px;font-size:14.67px;background-color:white !important">Below is the entry for today.</div>
<div style="margin:0px;font-size:14.67px;background-color:white !important"><br>
</div>
<div style="margin:0px;font-size:14.67px;background-color:white !important">25/01/2021 - Diary entry #437<br>
<br>
</div>
<blockquote style="font-size:14.67px;margin-top:0px;margin-bottom:0px;background-color:white !important">
<div style="margin:0px"></div>
<div style="margin:0px"></div>
<div style="margin:0px"></div>
<div style="margin:0px"></div>
<div style="margin:0px"></div>
<div style="margin:0px"></div>
In several of our previous Daily Diaries, we covered malware families using packers. Packers are tools used in binaries to compress/encrypt the binary code, possibly making the file smaller. In malware, packers are used to make binary analysis harder, keeping
 the malicious code encrypted in the file. When the binary starts, a small function loads the uncompressed/decrypted code in memory and executes like a regular binary. This week a previously undocumented malware packer was disclosed.
<div><br>
</div>
<div>This new packer is written in .NET. When executed, the packer drops or downloads an encoded DLL, which is decrypted by the custom function and then executed in memory. The custom decrypted function uses a XOR based algorithm, with the string "trump2020"
 being used as the key (newer samples used the key "trump2026"). The packer was named "DTPacker" due to those references to Donald Trump.</div>
<div><br>
</div>
DTPacker was found being used by several malware families, like Agent Tesla, Ave Maria RAT, AsyncRAT, Snake Keylogger and FormBook. This incident is a good example of how the cybercrime combines different malware from different sources when launching an attack.<span style="margin:0px"></span><span style="margin:0px"></span>
<div style="margin:0px"></div>
<div style="margin:0px"><br>
</div>
<div style="margin:0px"></div>
</blockquote>
<span style="margin:0px;font-size:14.67px;background-color:white !important">Kind Regards,</span></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<br>
</div>
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div>
<div></div>
<div></div>
<div></div>
<div></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<table style="font-family:"Times New Roman"; font-size:medium; text-align:start">
<tbody>
<tr>
<td width="180" align="left" style="width:180px">
<table width="120" align="left">
<tbody>
<tr>
<td colspan="3" align="center"><a href="https://www.appgate.com/"><img alt="" width="120" height="30" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/logo@2x.png"></a></td>
</tr>
<tr>
<td colspan="3" align="center"> </td>
</tr>
<tr>
<td width="37%" align="center"><a href="https://www.linkedin.com/company/appgate-security/"><img width="18" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/likedin@2x.png"></a></td>
<td width="28%"><a href="https://twitter.com/AppgateSecurity"><img width="20" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/twitter@2x.png"></a></td>
<td width="35%"><a href="https://www.youtube.com/channel/UC-8GvxcZbm-R3EJNl8jYjiQ"><img width="26" height="18" alt="" src="https://d3aafpijpsak2t.cloudfront.net/images/Signature/youtube@2x.png"></a></td>
</tr>
</tbody>
</table>
<p> </p>
</td>
<td width="350" colspan="2" rowspan="2" style="width:350px">
<p style="font-family:Arial,Helvetica,sans-serif; font-size:13px; color:rgb(12,12,12)">
<strong>Felipe Duarte Domingues</strong><br>
Security Researcher<br>
<strong>Appgate</strong></p>
<p style="font-family:Arial,Helvetica,sans-serif; font-size:13px; color:rgb(12,12,12)">
E:<span> </span><font color="#228ebe"><a href="mailto:felipe.duarte@appgate.com" title="mailto:felipe.duarte@appgate.com">felipe.duarte@appgate.com</a></font><br>
O: <span style="background-color:rgb(255,255,255); display:inline!important">+55 19 98840 2509</span></p>
</td>
</tr>
</tbody>
</table>
<br>
</div>
</div>
</div>
</div>
</body>
</html>