Manuel Statik Analiz (LLM Okumali) — Black Basta Ransomware (Linux ESXi Sifreleyici) | Tehdit: KRITIK
Dosya Kimligi
| SHA256 | a8894d8a71082d2a2d8799129eada9db0b280af6bfca02e9c3f214890bc67ea3 |
|---|---|
| Platform | Linux ELF (64-bit) |
| Hedef | VMware ESXi sunuculari |
| Boyut | 174.272 byte |
| Dil | C++ (GCC, ghc::filesystem) |
TOR C2 / Fidye Iletisim (Cleartext)
Kritik IOC: TOR hidden service adresi binary icerisinde cleartext olarak bulunmaktadir.
| TOR Onion URL | https://aazsbsgya565vlu2c6bzy6yfiebkcbtvvcytvolt33s77xypi7nypxyd.onion/ |
|---|---|
| TOR Browser | https://torproject.org |
Fidye Notu (Cleartext String)
DECRYPTION
Your data are stolen and encrypted
The data will be published on TOR website if you do not pay the ransom
You can contact us and decrypt one file for free on this TOR site
(you should download and install TOR browser first https://torproject.org)
https://aazsbsgya565vlu2c6bzy6yfiebkcbtvvcytvolt33s77xypi7nypxyd.onion/
Your data are stolen and encrypted
The data will be published on TOR website if you do not pay the ransom
You can contact us and decrypt one file for free on this TOR site
(you should download and install TOR browser first https://torproject.org)
https://aazsbsgya565vlu2c6bzy6yfiebkcbtvvcytvolt33s77xypi7nypxyd.onion/
Gelistirici Izi
C:/Users/dssd/Desktop/src Kullanici adi: dssd Proje: Desktop/src (dogrudan masaustu uzerinde gelistirilmis)
Teknik Ozellikler
- Linux ELF — VMware ESXi hipervizor ortamlarini hedefler
- ghc::filesystem C++ kutuphanesi ile dosya sistemi gezintisi
- pthread — coklu is parcacigi ile paralel sifreleme
- Cift gasp (double extortion): hem veri cikarimi hem de sifreleme
- Sifreleme sureleri loglanir: "Done time: X.XXXX seconds, encrypted: X.XXXX gb"
Black Basta Hakkinda
Black Basta, 2022 yilinda ortaya cikan ve Conti ransomware grubunun dagilmasinin ardından kurulan bir fidye yazilimi operasyonudur. Hem Windows hem de Linux (ESXi) hedefler. Cift gasp yontemiyle kurbanlardan hem sifre cozme ucreti hem de veri silmesi ucreti talep eder.
IOC
| SHA256 | a8894d8a71082d2a2d8799129eada9db0b280af6bfca02e9c3f214890bc67ea3 |
|---|---|
| TOR C2 | aazsbsgya565vlu2c6bzy6yfiebkcbtvvcytvolt33s77xypi7nypxyd.onion |
| Platform | Linux ELF (ESXi hedefi) |
| PDB Dev | dssd |
BlackBasta — Malware Profile
Black Basta ransomware grubu loaer/dropper. Microsoft Office Setup Engine (ose.pdb) olarak gizlenir. Global\OfficeSourceEngine64Mutex sahte mutex. Self-modifying .ex_cod section. Minimal import + runtime GetProcAddress API cozme. WinHttp C2. Token manipulasyonu.
Malware Type
Ransomware
Programming Language
C++
C2 Protocol
—
Target Systems
Windows/Linux
Capabilities & Behavior
Dosya Şifreleme (AES/RSA)
Gölge Kopya Silme
Yedek Kaldırma
Fidye Notu Oluşturma
Kalıcılık Sağlama
Ağ Paylaşımı Şifreleme
Anti-Analiz Teknikleri
Çift Gasp (Data Leak)
IOC List (1 indicators)
IOC — BlackBasta
# SHA256
a8894d8a71082d2a2d8799129eada9db0b280af6bfca02e9c3f214890bc67ea3
| Type | Value | Note |
|---|---|---|
| sha256 | a8894d8a71082d2a2d8799129eada9db0b280af6bfca02e9c3f214890bc67ea3 |
C2 Servers (1 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| aazsbsgya565vlu2c6bzy6yfiebkcbtvvcytvolt33s77xypi7nypxyd.onion | domain | 443 | — | inactive | — |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.