Derin Statik Analiz — NjRAT | Tehdit: high

Dosya Kimligi

SHA256d259aecd2b2feb2c9304c5e0d7c6f5f00fc7bc2db4cbd876339a39ed2c49f6c2
MD5b62d4b0851d859a8140f21074cc3edfb
SHA1d74b67d4ff94f3d60fc8b2ba62de1da2eb56e9a2
Boyut15328 byte
Tur/opt/ksentinel/samples/c559ae3589ef6275ab17974827435d17215a4f81b35da976a98299021
DerlemeBilinmiyor
PackerUPX
C2 Adresi: Sifrelenmis/obfuskeli config (statik analizle cozulemedi)

Yetenekler

  • Tespit edilemedi (obfuskeli)

Gelistirici Ipuclari

PDB Yolu: bash: -c: line 1: syntax error near unexpected token `|' bash: -c: line 1: `grep -oiE '[A-Za-z]:\\Users\\[^\\]{2,30}\\[^

PE Analizi

Binwalk / Packer

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------
0             0x0             Zip archive data, encrypted compressed size: 15

Aile Tespiti

String kaniti bulunamadi (sifrelenmis/obfuskeli).

NjRAT — Malware Profile

njRAT Bladabindi. Spanish cotizacion lure. get_Panel1 C2 panel. MENA + Latin America targeting.

Malware Type
RAT
Programming Language
VB.NET
C2 Protocol
TCP (varsayilan port 1177)
Target Systems
Windows
Also Known As (AKA)
Bladabindi, H-Worm, houdini

Technical Details

TCP port 1177 (varsayilan), XOR tabanlı iletisim sifreleme, .NET Framework 2.0+, Mutex: {GUID}, Registry Run key persistence, Keylogger (GetAsyncKeyState), clipboard monitor, screenshot, remote shell, remote camera

Attribution / Threat Actor

Arap dilli siber suc topluluklari, en cok MENA (Orta Dogu ve Kuzey Afrika) bolgesindeki gruplar. Yasama savasi donemi Suriyeli gruplar tarafindan da kullanilmistir.

Capabilities & Behavior

Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması

IOC List (5 indicators)

IOC — NjRAT
# d74b67d4ff94f3d60fc8b2ba62de1da2eb56e9a2 # SHA256 d259aecd2b2feb2c9304c5e0d7c6f5f00fc7bc2db4cbd876339a39ed2c49f6c2 # MD5 b62d4b0851d859a8140f21074cc3edfb # FILEPATH bash: -c: line 1: syntax error near unexpected token `|' # FILEPATH bash: -c: line 1: `grep -oiE '[A-Za-z]:\\[^\s\"'\'<>|*?]{5,150}' /tmp/all.txt | grep -viE '(msbuild|nuget|packages|Microsoft\.NET)' | sort -u | head -10'
TypeValueNote
d74b67d4ff94f3d60fc8b2ba62de1da2eb56e9a2
sha256 d259aecd2b2feb2c9304c5e0d7c6f5f00fc7bc2db4cbd876339a39ed2c49f6c2
md5 b62d4b0851d859a8140f21074cc3edfb
filepath bash: -c: line 1: syntax error near unexpected token `|'
filepath bash: -c: line 1: `grep -oiE '[A-Za-z]:\\[^\s\"'\'<>|*?]{5,150}' /tmp/all.txt | grep -viE '(msbuild|nuget|packages|Microsoft\.NET)' | sort -u | head -10'

C2 Servers (8 recorded servers for this family)

Address Type Port Protocol Status Country
system.io domain &mdash; TCP active &mdash;
microsoft.com domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
njratstatik-analizhighc2iocpe