Derin PE Analizi — TorRansomware | Tehdit: KRITIK
Dosya Kimligi
| SHA256 | 67a78b39e760e3460a135a7e4fa096ab6ce6b013658103890c866d9401928ba5 |
|---|---|
| Boyut | 1,261,752 byte |
| Derleyici | GCC 7.3-win32 MinGW-w64, 17 sections |
Tor C2: xri65fopcxkdfxhi4tidsg7cad.onion
xri65fopcxkdfxhi4tidsg7cad.onion -- Tor Hidden Service C2\nFidye odeme ve anahtar teslimi Onion aginda\nKurban Tor Browser ile sitenin acmali\nOperatorun kimligi gizli, sunucu yeri bilinemez
Kurban Secret Key
"with your secret key 6F2PQ14O2POZ1JB5PSD65HUJP19Y9DU1"\nRSA sifreleme: rsa_encrypt_key, rsa_encrypt_IV\nKurban bu key ile odeme yapar, operatorden decrypt key alir
Duvar Kagidi Hijack (Registry)
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop -> NoChangingWallPaper = 1\nHKLM\Policies\System -> Wallpaper = C:\Users\Public\bg.jpg\nKullanici degistiremez (NoChangingWallPaper=1)
SetThreadContext Enjeksiyon
SetThreadContext x3 referans -- process hollowing\nFPU anti-disassembly, TLS callback (1 func)
IOC
| SHA256 | 67a78b39e760e3460a135a7e4fa096ab6ce6b013658103890c866d9401928ba5 |
|---|---|
| Tor C2 | xri65fopcxkdfxhi4tidsg7cad.onion |
| Kurban Key | 6F2PQ14O2POZ1JB5PSD65HUJP19Y9DU1 |
| Fidye BG | C:\Users\Public\bg.jpg |
TorRansomware — Malware Profile
Tor .onion network kullanan C/C++ (GCC MinGW) ransomware. xri65fopcxkdfxhi4tidsg7cad.onion Tor C2. Kurban secret key: 6F2PQ14O2POZ1JB5PSD65HUJP19Y9DU1. RSA-encrypted file keys. Wallpaper hijack (C:\Users\Public\bg.jpg + NoChangingWallPaper=1). SetThreadContext process injection. 17 section obfuscation.
Malware Type
Ransomware
Programming Language
C (GCC MinGW)
C2 Protocol
Tor/.onion
Target Systems
Küresel
Capabilities & Behavior
Dosya Şifreleme (AES/RSA)
Gölge Kopya Silme
Yedek Kaldırma
Fidye Notu Oluşturma
Kalıcılık Sağlama
Ağ Paylaşımı Şifreleme
Anti-Analiz Teknikleri
Çift Gasp (Data Leak)
IOC List (1 indicators)
IOC — TorRansomware
# SHA256
67a78b39e760e3460a135a7e4fa096ab6ce6b013658103890c866d9401928ba5
| Type | Value | Note |
|---|---|---|
| sha256 | 67a78b39e760e3460a135a7e4fa096ab6ce6b013658103890c866d9401928ba5 |
C2 Servers (1 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| xri65fopcxkdfxhi4tidsg7cad.onion | domain | 80 | custom | inactive | — |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.