StealC .NET payload anti-debugging/anti-analysis strings
Detects .NET malicious payloads associated with the StealC info-stealer by identifying anti-debugging and anti-analysis routines. The rule specifically looks for the usage of System.Diagnostics.Debugger methods (IsAttached, IsLogging), native debugger presence checks (IsDebuggerPresent, CheckRemoteDebuggerPresent), and Environment.FailFast usage, often in combination with obfuscation markers like ConfuserEx.
YARA

