Dosya Kimligi
| SHA256 | e8444339164268d9950b137d7a23f09eb213b9e9fedb7d4a025b5f1075e3929c |
|---|---|
| Dosya | EmotetPayload32-bitDL (MalwareBazaar ismi) |
| Boyut | 193,536 byte (PE32 DLL x86, 4 sections) |
| Entropi | 3.920 (dusuk -- stage-1 loader veya sifresiz veri) |
| Imagebase | Suspicious |
| DOS stub | Suspicious |
Emotet Epoch Servisi: Tarihce
-- Emotet (Mealybug/Heodo/TA542): 2014-gunumuz aktif botnet\n-- Epoch1, Epoch2, Epoch3: Emotet ag bolumu/suru sistemi\n-- 32-bit DLL payload: Emotet loader mimarisi (regsvr32 veya rundll32)\n-- Dusuk entropi (3.92): sifresiz C kod veya XOR-steganografi\n-- ntdll.dll qsort/bsearch: surelis veri islemesi (kriptografi/arama)\n-- Suspicious imagebase + DOS stub: manuel PE yapimi gostergesi
Process Enumeration: Kurban Profili
KERNEL32.dll -> CreateToolhelp32Snapshot\nKERNEL32.dll -> Process32First\nKERNEL32.dll -> Process32Next\n\n-- CreateToolhelp32Snapshot: sistemdeki tum prosesleri listele\n-- Process32First + Process32Next: listeyi dolas\n-- Emotet kullanimi:\n 1. Sandbox/analiz araclarini tespit et (procmon, wireshark, sandboxie)\n 2. Hedef prosesleri bul (Outlook, Chrome) veri calma icin\n 3. Enjeksiyon hedefini sec (explorer.exe, svchost.exe)
Guvenlik ve Bellek Yonetimi
KERNEL32.dll -> VirtualAlloc\nKERNEL32.dll -> VirtualFree\nKERNEL32.dll -> VirtualProtect\nntdll.dll -> qsort, bsearch, wcslen\n\n-- VirtualAlloc + VirtualProtect: shellcode veya payload icin bellek hazirla\n-- ntdll dogrudan cagirma: KERNEL32 bypass denemeleri\n-- qsort/bsearch: veri siralamasi (C2 adres listesi siralamalari?)
IOC
| SHA256 | e8444339164268d9950b137d7a23f09eb213b9e9fedb7d4a025b5f1075e3929c |
|---|---|
| Tip | PE32 DLL (32-bit) -- Emotet payload |
| Etiket | EmotetPayload32-bitDL (MalwareBazaar dogrulama) |
| Process enum | CreateToolhelp32Snapshot + Process32First/Next |
| Bellek | VirtualAlloc + VirtualProtect (shellcode inject) |
Emotet — Malware Profile
Emotet (Heodo/Mealybug/TA542) 32-bit DLL payload. Process enumeration via CreateToolhelp32Snapshot+Process32First/Next. VirtualAlloc+VirtualProtect shellcode staging. ntdll.dll direct calls. Low entropy 3.92 (stage-1 loader/encoded payload). Suspicious imagebase and DOS stub.
Technical Details
C dili, HTTP C2 (RSA+AES sifreleme), modular yapi (email stealer, spreader, Outlook harvester), process hollowing, living off the land (regsvr32, mshta, certutil), Epoch1/2/3/4/5 botnet
Attribution / Threat Actor
TA542 (MUMMY SPIDER) - Ukrayna kokenli oldugu dusunulen organizasyon. 2021'de Europol/FBI tarafindan coguyla tutuklandi; 2022'de geri dondu.
Capabilities & Behavior
IOC List (1 indicators)
# SHA256
e8444339164268d9950b137d7a23f09eb213b9e9fedb7d4a025b5f1075e3929c
| Type | Value | Note |
|---|---|---|
| sha256 | e8444339164268d9950b137d7a23f09eb213b9e9fedb7d4a025b5f1075e3929c |
C2 Servers (7 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| 41.216.188.11 | ip | 8000 | HTTP | active | — |
| 103.143.173.206 | ip | 443 | HTTPS | inactive | ID |
| 144.91.65.153 | ip | 7080 | HTTP | inactive | DE |
| 195.88.54.144 | ip | 8080 | HTTP | sinkholed | — |
| 103.43.46.149 | ip | 443 | HTTPS | sinkholed | — |
| 185.220.101.32 | ip | 80 | HTTP | sinkholed | DE |
| 5.135.183.154 | ip | 8080 | HTTP | sinkholed | FR |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.