Manuel Statik Analiz (LLM Okumali) — UnixStealer (a310Logger) | Tehdit: KRITIK

Dosya Kimligi

SHA2560d6f87aa1826205087affc7248276844f30892bd62b3f96ec75d02ceeb8cc5b4
MB EtiketiBlackGuard / a310Logger (MB)
Gercek AdiUnixStealer (PDB'den)
Boyut303.617 byte
Platform.NET (C#)

Cleartext Discord Webhook C2 (KRITIK)

Discord Webhook (Exfiltrasyon):
https://discord.com/api/webhooks/1447625794359922871/P8qhcUhcDIHUGD1nOnDph6_jiieLZ1Pb53vxaOsrZQ6tHyNyb7SSCwCX0JcaaQZucT3f

Telegram Bot API (C2 Bildirim):
https://api.telegram.org/bot[TOKEN]

VimeWorld Dead Drop:
https://api.vimeworld.ru/user/name/
UYARI: Discord webhook ve Telegram Bot API adresleri cleartext string olarak PE icinde tespit edilmistir. Bu adresler araciligiyla calinti veri dogrudan saldirganin Discord kanaline ve Telegram botuna iletilmektedir.

Gelistirici Izi (PDB Sizdirmasi)

C:\Users\brtig\OneDrive\Desktop\Src\UnixStealer\UnixStealer\obj\Release\UnixStealer.pdb
Developer kullanici adi: brtig
Proje adi: UnixStealer
IDE: Visual Studio (Release Build)

Stealer Modulleri

ModulHedef
UnixStealer.ChromiumChrome, Brave, Edge — sifre/cookie/kredi karti
UnixStealer.EdgeMicrosoft Edge veritabani
GrabTelegramTelegram Desktop session
GetLocationSteamSteam ssfn + hesap bilgisi
BitcoinCoreBitcoin Core wallet.dat
WriteDiscordDiscord webhook exfiltrasyon modulu

IOC

SHA2560d6f87aa1826205087affc7248276844f30892bd62b3f96ec75d02ceeb8cc5b4
Discord Webhookhttps://discord.com/api/webhooks/1447625794359922871/P8qhcUhcDIHUGD1nOnDph6_jiieLZ1Pb53vxaOsrZQ6tHyNyb7SSCwCX0JcaaQZucT3f
C2api.telegram.org (bot), api.vimeworld.ru (dead drop)
Developerbrtig (OneDrive/Desktop)

UnixStealer — Malware Profile

UnixStealer (MB: a310Logger olarak etiketli), Discord webhook ve Telegram Bot API ile veri sızdiran .NET infostealerdir. Hedefler: Chrome/Edge/Brave sifreleri, Telegram Desktop session, Steam hesabi, Bitcoin Core wallet.dat. Gelistirici: brtig (PDB sizdirmasi).

Malware Type
Infostealer
Programming Language
C#/.NET
C2 Protocol
Discord Webhook/Telegram
Target Systems
Kuresel Bireysel

Capabilities & Behavior

Tarayıcı Kimlik Bilgileri
Çerez Hırsızlığı
Kripto Cüzdan Çalma
Sistem Bilgisi
Ekran Görüntüsü
FTP/SSH İstemci Şifreleri
E-posta İstemcisi Çalma
Veri Sızıntısı

IOC List (1 indicators)

IOC — UnixStealer
# SHA256 0d6f87aa1826205087affc7248276844f30892bd62b3f96ec75d02ceeb8cc5b4
TypeValueNote
sha256 0d6f87aa1826205087affc7248276844f30892bd62b3f96ec75d02ceeb8cc5b4

C2 Servers (3 recorded servers for this family)

Address Type Port Protocol Status Country
api.vimeworld.ru domain 443 HTTPS active —
api.telegram.org domain 443 HTTPS active —
discord.com/api/webhooks/1447625794359922871/P8qhcUhcDIHUGD1nOnDph6_jiieLZ1Pb53vxaOsrZQ6tHyNyb7SSCwCX0JcaaQZucT3f domain — HTTPS inactive —

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
unixstealera310loggerdiscord-webhooktelegram-c2discord-exfilsteamkriptopdb-leakedbrtig