Manuel Statik Analiz — SectopRAT/ArechClient2 | Tehdit: YUKSEK

Dosya Kimliği

SHA256e6cf4d8f6bb3fcc4794028b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5
Dosya Adıpuk3ta8cyv1.ps1 (obfüskülenmiş PowerShell)
Boyut794.028 byte
String Sayisi11.478

.su TLD C2 Domain

IOC: Sovyet .su TLD C2 — Rusça konuşan siber suçlu altyapısı!
gtLane6906.Su  -- .su (Sovyet Birliği) TLD C2 sunucusu
-- "gtLane" = gaming/betting platform taklidi?
-- "6906" = port veya kampanya numarası

Base64 C2 Config

rMZIRioWL/vSU4ZR4ovGIr0BSkpzKLjI2wAmKnRQ06dOGGYESdMJyi/8P2/exvSzzEH5XqF0k3c2obp3...
-- URL-safe olmayan Base64 → C2 server adres/port/şifreleme config

IOC

SHA256e6cf4d8f6bb3fcc4794028b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5
C2gtLane6906.Su

SectopRAT2 — Malware Profile

SectopRAT2 (ArechClient2). PowerShell dropper. .su TLD C2. Base64 config. Remote access+credential steal.

Malware Type
RAT
Programming Language
C#/.NET
C2 Protocol
TCP/HTTPS
Target Systems
Kuresel

Capabilities & Behavior

Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması

IOC List (1 indicators)

IOC — SectopRAT2
# SHA256 e6cf4d8f6bb3fcc4794028b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5
TypeValueNote
sha256 e6cf4d8f6bb3fcc4794028b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5

C2 Servers (1 recorded servers for this family)

Address Type Port Protocol Status Country
gtLane6906.su domain 443 HTTPS inactive —

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
sectopratarechclient2powershell-droppersu-tldgtlane6906base64-config