Dosya Kimligi
| SHA256 | 3af64c28e0cedf48abc217049af66c23149fd27a1e5a57ae39afb4b98d4d3d41 |
|---|---|
| Boyut | 1.667.072 byte (1.6MB) |
| String Sayisi | 7.169 |
Sifrelenmis C2 Konfigurasyonu
!C2Dv% -- C2 config sekman baslik imzasi (sifrelenmis) F8C2YKa -- C2 referansi (sifrelenmis) ]HC2& -- C2 referansi (sifrelenmis)
SystemBC Hakkinda
SystemBC, 2019'da ortaya cikan bir C++ SOCKS5 proxy backdoor'dur. Cobalt Strike beacon ve diger payloadlardan gelen ag trafiklerini mesgru gordurmek icin tasarlanmistir. Ryuk, Conti, BlackMatter, Cl0p ve Egregor ransomware operasyonlarinda "network relay" katmani olarak kullanilmistir. C2 adresi RC4 ile sifrelenmis binary config icindedir.
IOC
| SHA256 | 3af64c28e0cedf48abc217049af66c23149fd27a1e5a57ae39afb4b98d4d3d41 |
|---|---|
| Protokol | SOCKS5 Proxy |
| C2 | RC4 sifrelenmis config |
SystemBC — Malware Profile
SystemBC proxy botnet. Embedded TLS private key BEGIN/END PRIVATE KEY PEM. Tor SOCKS5 proxy tunnel. Used by Ryuk/Conti/DoppelPaymer ransomware for C2 tunneling.
Technical Details
Backdoor ailesi: TCP/HTTP C2, gizli uzak erisim, kalicilik mekanizmasi (servis/Registry), shell komutu calistirma, dosya transfer, anti-forensic teknikleri
Capabilities & Behavior
IOC List (1 indicators)
# SHA256
3af64c28e0cedf48abc217049af66c23149fd27a1e5a57ae39afb4b98d4d3d41
| Type | Value | Note |
|---|---|---|
| sha256 | 3af64c28e0cedf48abc217049af66c23149fd27a1e5a57ae39afb4b98d4d3d41 |
C2 Servers (1 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| 134.255.218.162 | ip | 4001 | TCP | inactive | LV |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.