Malware
PNGLoad
According to ESET Research, PNGLoad is a second-stage payload deployed by Worok on compromised systems and loaded either by CLRLoad or PowHeartBeat.
PNGLoad is a Windows malware family.
Background
ESET Research reports that PNGLoad serves as a second-stage payload that Worok plants on compromised hosts, loaded by either CLRLoad or PowHeartBeat. It can fetch and run further payloads from a C&C server, which is probably the route by which attackers delivered PNGLoad onto machines already compromised with PowHeartBeat. As its name implies, PNGLoad is a loader that assembles an executable payload from bytes taken out of PNG files. The sample is a 64-bit .NET executable obfuscated with .NET Reactor that poses as legitimate software.
Source: Malpedia (Fraunhofer FKIE).