Statik Analiz — Emotet Payload DLL | Tehdit: KRITIK

Dosya Kimligi

SHA256e8444339164268d9950b137d7a23f09eb213b9e9fedb7d4a025b5f1075e3929c
DosyaEmotetPayload32-bitDL (MalwareBazaar ismi)
Boyut193,536 byte (PE32 DLL x86, 4 sections)
Entropi3.920 (dusuk -- stage-1 loader veya sifresiz veri)
ImagebaseSuspicious
DOS stubSuspicious

Emotet Epoch Servisi: Tarihce

EMOTET: MalwareBazaar etiketiyle "EmotetPayload32-bitDL" -- tescilli Emotet botnet payload!
-- Emotet (Mealybug/Heodo/TA542): 2014-gunumuz aktif botnet\n-- Epoch1, Epoch2, Epoch3: Emotet ag bolumu/suru sistemi\n-- 32-bit DLL payload: Emotet loader mimarisi (regsvr32 veya rundll32)\n-- Dusuk entropi (3.92): sifresiz C kod veya XOR-steganografi\n-- ntdll.dll qsort/bsearch: surelis veri islemesi (kriptografi/arama)\n-- Suspicious imagebase + DOS stub: manuel PE yapimi gostergesi

Process Enumeration: Kurban Profili

KERNEL32.dll -> CreateToolhelp32Snapshot\nKERNEL32.dll -> Process32First\nKERNEL32.dll -> Process32Next\n\n-- CreateToolhelp32Snapshot: sistemdeki tum prosesleri listele\n-- Process32First + Process32Next: listeyi dolas\n-- Emotet kullanimi:\n  1. Sandbox/analiz araclarini tespit et (procmon, wireshark, sandboxie)\n  2. Hedef prosesleri bul (Outlook, Chrome) veri calma icin\n  3. Enjeksiyon hedefini sec (explorer.exe, svchost.exe)

Guvenlik ve Bellek Yonetimi

KERNEL32.dll -> VirtualAlloc\nKERNEL32.dll -> VirtualFree\nKERNEL32.dll -> VirtualProtect\nntdll.dll -> qsort, bsearch, wcslen\n\n-- VirtualAlloc + VirtualProtect: shellcode veya payload icin bellek hazirla\n-- ntdll dogrudan cagirma: KERNEL32 bypass denemeleri\n-- qsort/bsearch: veri siralamasi (C2 adres listesi siralamalari?)

IOC

SHA256e8444339164268d9950b137d7a23f09eb213b9e9fedb7d4a025b5f1075e3929c
TipPE32 DLL (32-bit) -- Emotet payload
EtiketEmotetPayload32-bitDL (MalwareBazaar dogrulama)
Process enumCreateToolhelp32Snapshot + Process32First/Next
BellekVirtualAlloc + VirtualProtect (shellcode inject)

Emotet — Malware Profile

Emotet (Heodo/Mealybug/TA542) 32-bit DLL payload. Process enumeration via CreateToolhelp32Snapshot+Process32First/Next. VirtualAlloc+VirtualProtect shellcode staging. ntdll.dll direct calls. Low entropy 3.92 (stage-1 loader/encoded payload). Suspicious imagebase and DOS stub.

Malware Type
Loader
Programming Language
C
C2 Protocol
HTTP
Target Systems
Windows
Also Known As (AKA)
Heodo

Technical Details

C dili, HTTP C2 (RSA+AES sifreleme), modular yapi (email stealer, spreader, Outlook harvester), process hollowing, living off the land (regsvr32, mshta, certutil), Epoch1/2/3/4/5 botnet

Attribution / Threat Actor

TA542 (MUMMY SPIDER) - Ukrayna kokenli oldugu dusunulen organizasyon. 2021'de Europol/FBI tarafindan coguyla tutuklandi; 2022'de geri dondu.

Capabilities & Behavior

Payload İndirme
Süreç Enjeksiyonu
Modüler Mimari
Kimlik Bilgisi Hırsızlığı
Yanal Hareket
Kalıcılık
Anti-VM/Sandbox
İkincil Payload Dağıtımı

IOC List (1 indicators)

IOC — Emotet
# SHA256 e8444339164268d9950b137d7a23f09eb213b9e9fedb7d4a025b5f1075e3929c
TypeValueNote
sha256 e8444339164268d9950b137d7a23f09eb213b9e9fedb7d4a025b5f1075e3929c

C2 Servers (7 recorded servers for this family)

Address Type Port Protocol Status Country
41.216.188.11 ip 8000 HTTP active —
103.143.173.206 ip 443 HTTPS inactive ID
144.91.65.153 ip 7080 HTTP inactive DE
195.88.54.144 ip 8080 HTTP sinkholed —
103.43.46.149 ip 443 HTTPS sinkholed —
185.220.101.32 ip 80 HTTP sinkholed DE
5.135.183.154 ip 8080 HTTP sinkholed FR

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
emotetpayloaddllemotetemotet-epochheodo-mealybug-ta542emotetpayload32-bitdl-malwarebazaar-confirmed-tagcreatetoolhelp32snapshot-process32first-process32next-process-enumerationntdll-dll-direct-qsort-bsearch-wcslenvirtualalloc-virtualprotect-shellcode-injectionsuspicious-imagebase-suspicious-dos-stublow-entropy-3-920-stage1-loader-theory