Dosya Kimliği
| SHA256 | 123a833c6ad4fefb0e612a93c8bfb2fda9525414b308f18c9d3ea56a5ea37fff |
|---|---|
| Boyut | 1.007.633 byte (984KB) |
| String Sayisi | 6.342 |
fromChrome9September9 + oHbullshitibChromej2 + boobsrChromeannouncedFirefox: Geliştiricinin Küfürlü Obfuscation
fromChrome9September9 -- "Chrome" + tarih ref
oHbullshitibChromej2 -- "bullshit" + "Chrome"
boobsrChromeannouncedFirefoxatheofaultedM -- "boobs" + "Chrome" + "Firefox"
-- Obfuscation tekniği: meşru kelimeler ("Chrome", "September") + vulgar sözcükler
-- "bullshit" + "boobs" = geliştiricinin yorumları string içinde kaybolmuş
-- Karakterler araya sıkıştırılmış: "from" + "Chrome" + "9" + "September" + "9"
-- Hedef: Chrome + Firefox credential extraction
-- Developer: vulgar string'leri obfuscation malzemesi olarak kullandı
-- Benzer pattern: Dridex'in karakteristik string encoding tekniği
DuiNavigate@DirectUI: C++ RTTI — Windows Shell Framework
??4DuiNavigate@DirectUI@@QEAAAEAV01@A -- "DuiNavigate" = DirectUI navigation (Windows shell UI framework) -- "DirectUI" = Windows shell rendering engine (IE, Explorer) -- C++ RTTI mangled name: "??4" = assignment operator -- "@@QEAAAEAV01@A" = x64 C++ calling convention -- Dridex: DirectUI hook → tarayıcı form verisi hook için Windows shell UI kullanır -- Browser form hooking: kullanıcı web form doldururken şifreleri yakalar
IOC
| SHA256 | 123a833c6ad4fefb0e612a93c8bfb2fda9525414b308f18c9d3ea56a5ea37fff |
|---|---|
| Hedef | Chrome + Firefox (form hooking) |
Dridex — Malware Profile
Dridex Bugat TA505 banking trojan. Chrome/Firefox form hooking with obfuscated strings. DirectUI RTTI.
Technical Details
Dridex (Bugat/Cridex) is a modular banking trojan operated by TA505/Evil Corp since 2011. Uses peer-to-peer botnet architecture for C2 communication to resist takedowns. Modules: form grabber, VNC backdoor, network proxy, credential stealer, spread module. Encrypted communication: RC4 + custom protocol over HTTP. Delivered via Microsoft Office macro phishing (VBA macros). Used to deliver: BitPaymer, WastedLocker, Grief (PayOrGrief) ransomware. Evil Corp sanctioned by US Treasury October 2019, making ransom payments illegal for US entities. Dridex infrastructure heavily overlaps with Locky ransomware campaigns. Botnet IDs (bot IDs): 220, 444, 7777, multiple active botnets simultaneously.
Attribution / Threat Actor
Evil Corp (TA505), Maksim Yakubets (indicted by FBI)
Capabilities & Behavior
IOC List (1 indicators)
# SHA256
123a833c6ad4fefb0e612a93c8bfb2fda9525414b308f18c9d3ea56a5ea37fff
| Type | Value | Note |
|---|---|---|
| sha256 | 123a833c6ad4fefb0e612a93c8bfb2fda9525414b308f18c9d3ea56a5ea37fff |
C2 Servers (3 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| 79.141.164.52 | ip | 4444 | TCP | sinkholed | RO |
| 185.234.218.151 | ip | 4444 | HTTPS | sinkholed | RU |
| 77.73.133.84 | ip | 443 | HTTPS | sinkholed | BG |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.