Dosya Kimligi
| SHA256 | 39cbd2d2299ebbc190929763242f8f854188b405ac7f5ba7bed3e4ba2a59dc4f |
|---|---|
| Boyut | 95.232 byte |
| String Sayisi | 998 |
VB.NET / .NET Kaniti
MulticastDelegate, DelegateCallback, DelegateAsyncState LateSet, LateSetComplex -- VB.NET late binding FileStream, FileSystemInfo, GetFiles -- .NET IO System.IO, System.Me, System.Ru -- False pozitif (.NET namespace) RegValueSet -- Registry yazma
NjRAT Hakkinda
NjRAT (Bladabindi/H-Worm), 2012'de ortaya cikan VB.NET tabanli bir RAT ailesidir. TCP C2 ile keylogger, ekran yakalama, dosya yonetimi, uzaktan shell, plugin sistemi destekler. Orta Dogu ve Kuzey Afrika'da yaygin. Acik kaynak versiyonlari underground forumlarda ucretsiz.
IOC
| SHA256 | 39cbd2d2299ebbc190929763242f8f854188b405ac7f5ba7bed3e4ba2a59dc4f |
|---|---|
| Dil | VB.NET |
| C2 | TCP (sifrelenmis) |
NjRAT — Malware Profile
njRAT Bladabindi. Spanish cotizacion lure. get_Panel1 C2 panel. MENA + Latin America targeting.
Technical Details
TCP port 1177 (varsayilan), XOR tabanlı iletisim sifreleme, .NET Framework 2.0+, Mutex: {GUID}, Registry Run key persistence, Keylogger (GetAsyncKeyState), clipboard monitor, screenshot, remote shell, remote camera
Attribution / Threat Actor
Arap dilli siber suc topluluklari, en cok MENA (Orta Dogu ve Kuzey Afrika) bolgesindeki gruplar. Yasama savasi donemi Suriyeli gruplar tarafindan da kullanilmistir.
Capabilities & Behavior
IOC List (1 indicators)
# SHA256
39cbd2d2299ebbc190929763242f8f854188b405ac7f5ba7bed3e4ba2a59dc4f
| Type | Value | Note |
|---|---|---|
| sha256 | 39cbd2d2299ebbc190929763242f8f854188b405ac7f5ba7bed3e4ba2a59dc4f |
C2 Servers (8 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| system.io | domain | — | TCP | active | — |
| microsoft.com | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.