Derin Statik Analiz — StealC | Tehdit: high

Dosya Kimligi

SHA256f3aa7c12cd3ea1338522720d746902747e75f1094aff964ba2b6417ca57e876f
MD509335a94e66e63edf675f2f8cfef5104
SHA14110a19cb96650821f8922bbfb61526795280b28
Boyut1609953 byte
Tur/opt/ksentinel/samples/b9505282931ce70307a14689daf7767ba1124113c24c7e174499bb533
DerlemeBilinmiyor
PackerUPX
C2 Adresi: Sifrelenmis/obfuskeli config (statik analizle cozulemedi)

Yetenekler

  • Tespit edilemedi (obfuskeli)

SMTP Konfigurasyonu

"J4tO:
otO:\

Gelistirici Ipuclari

PDB Yolu: bash: -c: line 1: syntax error near unexpected token `|' bash: -c: line 1: `grep -oiE '[A-Za-z]:\\Users\\[^\\]{2,30}\\[^

Email: 9c@o.Ux

Telegram: @3puOLj @DIfY @dO4lO @GmL8 @iJfx

PE Analizi

Binwalk / Packer

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------
0             0x0             Zip archive data, encrypted compressed size: 16

Aile Tespiti

String kaniti bulunamadi (sifrelenmis/obfuskeli).

StealC — Malware Profile

StealC, 2023 yilinda ortaya cikan Go (Golang) tabanlı bir MaaS infostealer ailesidir. Vidar ve Raccoon kaynak kodundan ilham alinarak gelistirildigi dusunulmektedir. 30+ tarayici, kripto cuzdan, FTP istemcisi, email ve Discord/Telegram token hedefler.

Malware Type
Infostealer
Programming Language
C
C2 Protocol
HTTP
Target Systems
Windows

Technical Details

C dili, HTTP POST C2, browser stealer (Chromium/Firefox), kripto wallet stealer (50+ tarayici eklentisi), Telegram stealer, Steam, Discord token stealer, fingerprint modulu

Capabilities & Behavior

Tarayıcı Kimlik Bilgileri
Çerez Hırsızlığı
Kripto Cüzdan Çalma
Sistem Bilgisi
Ekran Görüntüsü
FTP/SSH İstemci Şifreleri
E-posta İstemcisi Çalma
Veri Sızıntısı

IOC List (5 indicators)

IOC — StealC
# 4110a19cb96650821f8922bbfb61526795280b28 # SHA256 f3aa7c12cd3ea1338522720d746902747e75f1094aff964ba2b6417ca57e876f # MD5 09335a94e66e63edf675f2f8cfef5104 # FILEPATH bash: -c: line 1: syntax error near unexpected token `|' # FILEPATH bash: -c: line 1: `grep -oiE '[A-Za-z]:\\[^\s\"'\'<>|*?]{5,150}' /tmp/all.txt | grep -viE '(msbuild|nuget|packages|Microsoft\.NET)' | sort -u | head -10'
TypeValueNote
4110a19cb96650821f8922bbfb61526795280b28
sha256 f3aa7c12cd3ea1338522720d746902747e75f1094aff964ba2b6417ca57e876f
md5 09335a94e66e63edf675f2f8cfef5104
filepath bash: -c: line 1: syntax error near unexpected token `|'
filepath bash: -c: line 1: `grep -oiE '[A-Za-z]:\\[^\s\"'\'<>|*?]{5,150}' /tmp/all.txt | grep -viE '(msbuild|nuget|packages|Microsoft\.NET)' | sort -u | head -10'

C2 Servers (4 recorded servers for this family)

Address Type Port Protocol Status Country
www.pakistani.org domain &mdash; HTTP active &mdash;
45.87.152.64 ip 80 HTTP inactive NL
185.174.137.219 ip 80 HTTP inactive RU
godebugs.Info domain &mdash; HTTP inactive &mdash;

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
stealcstatik-analizhighc2iocpe