Derin Statik Analiz — XWorm | Tehdit: critical
Dosya Kimligi
| SHA256 | f6a217781a6a94183c3fdfffaf10365890a2742ba9e934e96542976c57a0e7e1 |
|---|---|
| MD5 | bc43b592bc51481834d38098de3cb999 |
| SHA1 | 432501eecbf6f81c63aa4dc7189722d8ce63559d |
| Boyut | 1752822 byte |
| Tur | /opt/ksentinel/samples/ddfbf3db2b7e15b8202b71e1e97a180a54a3b248cbc9347d044b33886 |
| Derleme | Bilinmiyor |
| Packer | UPX |
C2 Adresi: Sifrelenmis/obfuskeli config (statik analizle cozulemedi)
Yetenekler
- Tespit edilemedi (obfuskeli)
Gelistirici Ipuclari
PDB Yolu: bash: -c: line 1: syntax error near unexpected token `|'
bash: -c: line 1: `grep -oiE '[A-Za-z]:\\Users\\[^\\]{2,30}\\[^
Telegram: @1aQv @2L4F @6Be2Z @6XAy_ @8kLKz
PE Analizi
Binwalk / Packer
DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 0 0x0 Zip archive data, encrypted compressed size: 17
Aile Tespiti
String kaniti bulunamadi (sifrelenmis/obfuskeli).
XWorm — Malware Profile
XWorm RAT .NET. Contract.exe is sozlesmesi. RecargarPanels Ispanyolca UI. panelActions plugin. Aggregate modül.
Malware Type
RAT
Programming Language
.NET C#
C2 Protocol
TCP
Target Systems
Windows
Technical Details
C# .NET, AES-128-CBC veya AES-256, TCP varsayilan port 7878, Anti-VM (GetSystemFirmwareTable), Anti-debug (FindWindow Olly/x64dbg), Webhook stealer, Clipper, HVNC, Remote Shell, Ransomware modulu
Capabilities & Behavior
Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması
IOC List (5 indicators)
IOC — XWorm
#
432501eecbf6f81c63aa4dc7189722d8ce63559d
# SHA256
f6a217781a6a94183c3fdfffaf10365890a2742ba9e934e96542976c57a0e7e1
# MD5
bc43b592bc51481834d38098de3cb999
# FILEPATH
bash: -c: line 1: syntax error near unexpected token `|'
# FILEPATH
bash: -c: line 1: `grep -oiE '[A-Za-z]:\\[^\s\"'\'<>|*?]{5,150}' /tmp/all.txt | grep -viE '(msbuild|nuget|packages|Microsoft\.NET)' | sort -u | head -10'
| Type | Value | Note |
|---|---|---|
| 432501eecbf6f81c63aa4dc7189722d8ce63559d | ||
| sha256 | f6a217781a6a94183c3fdfffaf10365890a2742ba9e934e96542976c57a0e7e1 | |
| md5 | bc43b592bc51481834d38098de3cb999 | |
| filepath | bash: -c: line 1: syntax error near unexpected token `|' | |
| filepath | bash: -c: line 1: `grep -oiE '[A-Za-z]:\\[^\s\"'\'<>|*?]{5,150}' /tmp/all.txt | grep -viE '(msbuild|nuget|packages|Microsoft\.NET)' | sort -u | head -10' |
C2 Servers (8 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| system.io | domain | — | TCP | active | — |
| eIL.ru | domain | — | TCP | active | — |
| exec.in | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.