Statik Analiz — BluStealer | YÜKSEK | CVSS: 7.5
Dosya
| SHA256 | f7206d9e9216ea73a6c530c165866ed0d8605b7f549754c06d6599366ef04441 |
|---|---|
| MD5 | 50a1ee46c4a23ce01fc2a3dbeeae0957 |
| Dosya | f7206d9e9216ea73a6c530c165866ed0d8605b7f549754c06d6599366ef04441.exe |
| Boyut | 1,129,216 byte |
| Tür | PE32 executable for MS Windows 6.00 (console), Intel i386, 7 sections |
| Stringler | 1,296 |
PDB:
C:\k5HhgezkEfMst1yyTptSMhC3UKvaLmH6\Ghost.pdbBölümler
| Ad | Entropi |
|---|---|
.text | 5.85 |
.rdata | 4.42 |
.data | 3.25 |
.idata | 4.47 |
.BSS | 5.41 |
.00cfg | 0.11 |
.reloc | 6.09 |
Import Tablosu
GDI32.dllKERNEL32.dll
IOC
| SHA256 | f7206d9e9216ea73a6c530c165866ed0d8605b7f549754c06d6599366ef04441 |
|---|---|
| MD5 | 50a1ee46c4a23ce01fc2a3dbeeae0957 |
| PDB | C:\k5HhgezkEfMst1yyTptSMhC3UKvaLmH6\Ghost.pdb |
BluStealer — Malware Profile
BluStealer VB6/VBS stealer 2021. Telegram Bot /sendDocument C2. TSC developer. Tarayici+email+kripto.
Malware Type
Infostealer
Programming Language
VB6/VBScript
C2 Protocol
Telegram Bot API
Target Systems
Küresel
Capabilities & Behavior
Tarayıcı Kimlik Bilgileri
Çerez Hırsızlığı
Kripto Cüzdan Çalma
Sistem Bilgisi
Ekran Görüntüsü
FTP/SSH İstemci Şifreleri
E-posta İstemcisi Çalma
Veri Sızıntısı
IOC List (1 indicators)
IOC — BluStealer
# FILEPATH
C:\k5HhgezkEfMst1yyTptSMhC3UKvaLmH6\Ghost.pdb
| Type | Value | Note |
|---|---|---|
| filepath | C:\k5HhgezkEfMst1yyTptSMhC3UKvaLmH6\Ghost.pdb | PDB |
C2 Servers (8 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| digicert.com | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| sectigo.com | domain | — | TCP | active | — |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.