Derin Statik Analiz — XWorm | Tehdit: critical

Dosya Kimligi

SHA256f6a217781a6a94183c3fdfffaf10365890a2742ba9e934e96542976c57a0e7e1
MD5bc43b592bc51481834d38098de3cb999
SHA1432501eecbf6f81c63aa4dc7189722d8ce63559d
Boyut1752822 byte
Tur/opt/ksentinel/samples/ddfbf3db2b7e15b8202b71e1e97a180a54a3b248cbc9347d044b33886
DerlemeBilinmiyor
PackerUPX
C2 Adresi: Sifrelenmis/obfuskeli config (statik analizle cozulemedi)

Yetenekler

  • Tespit edilemedi (obfuskeli)

Gelistirici Ipuclari

PDB Yolu: bash: -c: line 1: syntax error near unexpected token `|' bash: -c: line 1: `grep -oiE '[A-Za-z]:\\Users\\[^\\]{2,30}\\[^

Telegram: @1aQv @2L4F @6Be2Z @6XAy_ @8kLKz

PE Analizi

Binwalk / Packer

DECIMAL       HEXADECIMAL     DESCRIPTION
--------------------------------------------------------------------------------
0             0x0             Zip archive data, encrypted compressed size: 17

Aile Tespiti

String kaniti bulunamadi (sifrelenmis/obfuskeli).

XWorm — Malware Profile

XWorm RAT .NET. Contract.exe is sozlesmesi. RecargarPanels Ispanyolca UI. panelActions plugin. Aggregate modül.

Malware Type
RAT
Programming Language
.NET C#
C2 Protocol
TCP
Target Systems
Windows

Technical Details

C# .NET, AES-128-CBC veya AES-256, TCP varsayilan port 7878, Anti-VM (GetSystemFirmwareTable), Anti-debug (FindWindow Olly/x64dbg), Webhook stealer, Clipper, HVNC, Remote Shell, Ransomware modulu

Capabilities & Behavior

Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması

IOC List (5 indicators)

IOC — XWorm
# 432501eecbf6f81c63aa4dc7189722d8ce63559d # SHA256 f6a217781a6a94183c3fdfffaf10365890a2742ba9e934e96542976c57a0e7e1 # MD5 bc43b592bc51481834d38098de3cb999 # FILEPATH bash: -c: line 1: syntax error near unexpected token `|' # FILEPATH bash: -c: line 1: `grep -oiE '[A-Za-z]:\\[^\s\"'\'<>|*?]{5,150}' /tmp/all.txt | grep -viE '(msbuild|nuget|packages|Microsoft\.NET)' | sort -u | head -10'
TypeValueNote
432501eecbf6f81c63aa4dc7189722d8ce63559d
sha256 f6a217781a6a94183c3fdfffaf10365890a2742ba9e934e96542976c57a0e7e1
md5 bc43b592bc51481834d38098de3cb999
filepath bash: -c: line 1: syntax error near unexpected token `|'
filepath bash: -c: line 1: `grep -oiE '[A-Za-z]:\\[^\s\"'\'<>|*?]{5,150}' /tmp/all.txt | grep -viE '(msbuild|nuget|packages|Microsoft\.NET)' | sort -u | head -10'

C2 Servers (8 recorded servers for this family)

Address Type Port Protocol Status Country
system.io domain &mdash; TCP active &mdash;
eIL.ru domain &mdash; TCP active &mdash;
exec.in domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;
system.io domain &mdash; TCP active &mdash;

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
xwormstatik-analizcriticalc2iocpe