Derin Statik Analiz — XWorm | Tehdit: high

Dosya Kimliği

SHA256ddfbf3db2b7e15b8202b71e1e97a180a54a3b248cbc9347d044b338862086d09
MD574a5fb2edb6d0cdde2751397f5c97b42
SHA1a644446dbf866b282e70f98bf550829c5383e894
Dosya AdıSCAN DOC FILE PR 0001000265.JS
Boyut4186364 byte
Tür/opt/ksentinel/samples/ddfbf3db2b7e15b8_SCANDOCFILEPR00010002: Unicode text, UTF-8 text, with very l
Derleme TarihiBilinmiyor
PackerUPX

Ağ IOC'u tespit edilemedi (obfuscated/encrypted config).

Yetenekler

Base64 Decode:

B64:LGTANBCASTVVSWVEPPXX/LGTANBCASTVVSWVEPPXX => I5UIeD<
B64:LGTANBCASTVVSWVEUX+LGTANBCASTVVSWVELKKK => I5UIeDQ
MURYQ
B64:LGTANBCASTVVSWVEZCVV+LGTANBCASTVVSWVEZCVVV => I5UIeDd%U
B64:+scriptName+LGTANB

Geliştirici İpuçları

Geliştirici ipucu bulunamadı.

PE Analizi

PE analizi mevcut değil.

Aile Tespiti — String Kanıtı

String kanıtı bulunamadı (obfuscated).

XWorm — Malware Profile

XWorm RAT .NET. Contract.exe is sozlesmesi. RecargarPanels Ispanyolca UI. panelActions plugin. Aggregate modül.

Malware Type
RAT
Programming Language
.NET C#
C2 Protocol
TCP
Target Systems
Windows

Technical Details

C# .NET, AES-128-CBC veya AES-256, TCP varsayilan port 7878, Anti-VM (GetSystemFirmwareTable), Anti-debug (FindWindow Olly/x64dbg), Webhook stealer, Clipper, HVNC, Remote Shell, Ransomware modulu

Capabilities & Behavior

Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması

IOC List (3 indicators)

IOC — XWorm
# a644446dbf866b282e70f98bf550829c5383e894 # SHA256 ddfbf3db2b7e15b8202b71e1e97a180a54a3b248cbc9347d044b338862086d09 # MD5 74a5fb2edb6d0cdde2751397f5c97b42
TypeValueNote
a644446dbf866b282e70f98bf550829c5383e894
sha256 ddfbf3db2b7e15b8202b71e1e97a180a54a3b248cbc9347d044b338862086d09
md5 74a5fb2edb6d0cdde2751397f5c97b42

C2 Servers (8 recorded servers for this family)

Address Type Port Protocol Status Country
system.io domain &mdash; TCP active &mdash;
eIL.ru domain &mdash; TCP active &mdash;
exec.in domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
xwormstatik-analizhighc2iocpe-analiz