Investigation of 0debug Stealer Using Assisted Static Analysis Method
This study investigates the capabilities of the identified 0debug Stealer malware through qualitative static analysis and reverse engineering. This study primarily employs non-executional static techniques, such as fingerprinting, decompiling, and string extraction, with a bit of dynamic analysis used primarily for deobfuscation. Analysis confirms that obfuscation hinders direct examination, yet reveals core functionalities of 1) anti-tampering, anti-VM, and anti-sniffer to evade detection 2) data theft targeting important victim information, and 3) Command and Control exfiltration. Findings demonstrate 0debug Stealer’s capabilities in bypassing traditional security measures, emphasising the critical role of static analysis in dissecting advanced threats. This paper contributes to the forensic analysis of emerging threats by providing a detailed examination of the 0debug Stealer's manner, revealing its evasion techniques and comprehensive data theft capabilities.