Dosya Kimligi
| SHA256 | b804a5b07e90170c3640e0c0bfc6af38bccc8abbafbffe132a1808d6d0f24cae |
|---|---|
| Boyut | 802.816 byte |
| String Sayisi | 2.394 (sifrelenmis) |
Analiz
Dridex, tum konfigurasyonunu (C2 listesi, web inject kurallar, hedef bankalarin URL'leri) sifrelenmis XML blob'larinda saklar. Statik string analizinde cleartext IOC bulunamadi.
Dridex Mimarisi
| Modul | Fonksiyon |
|---|---|
| Loader (core) | C2 haberlesme, modul indirme, anti-analiz |
| Web Inject | MITB (Man-in-the-Browser) bankacilik sayfasi manipulasyonu |
| Botnet | P2P C2 haberlesme (EB3 protokol) |
| Credential Harvester | Tarayici sifre, form veri calma |
| Spam Module | Banka hesap bilgisi icin kimlik avı email gondermek |
Dridex Hakkinda
Dridex (Evil Corp/TA505 iliskilendirilir), 2011'de Cridex'ten turetilen ve bankaci trojan'lar icinde en gelismis olanlarindan biridir. UK ve US bankacilik sistemlerini yoğun olarak hedef almistir. P2P botnet mimarisi sayesinde tek nokta C2 altyapi cokusuna direnclidir. Evil Corp uyeleri 2019'da ABD tarafindan yargilanmis, ancak Rusya'da serbestce faaliyet gosterdigi bilinmektedir.
IOC
| SHA256 | b804a5b07e90170c3640e0c0bfc6af38bccc8abbafbffe132a1808d6d0f24cae |
|---|---|
| C2 | P2P sifrelenmis (XOR/RC4) |
Dridex — Malware Profile
Dridex Bugat TA505 banking trojan. Chrome/Firefox form hooking with obfuscated strings. DirectUI RTTI.
Technical Details
Dridex (Bugat/Cridex) is a modular banking trojan operated by TA505/Evil Corp since 2011. Uses peer-to-peer botnet architecture for C2 communication to resist takedowns. Modules: form grabber, VNC backdoor, network proxy, credential stealer, spread module. Encrypted communication: RC4 + custom protocol over HTTP. Delivered via Microsoft Office macro phishing (VBA macros). Used to deliver: BitPaymer, WastedLocker, Grief (PayOrGrief) ransomware. Evil Corp sanctioned by US Treasury October 2019, making ransom payments illegal for US entities. Dridex infrastructure heavily overlaps with Locky ransomware campaigns. Botnet IDs (bot IDs): 220, 444, 7777, multiple active botnets simultaneously.
Attribution / Threat Actor
Evil Corp (TA505), Maksim Yakubets (indicted by FBI)
Capabilities & Behavior
IOC List (1 indicators)
# SHA256
b804a5b07e90170c3640e0c0bfc6af38bccc8abbafbffe132a1808d6d0f24cae
| Type | Value | Note |
|---|---|---|
| sha256 | b804a5b07e90170c3640e0c0bfc6af38bccc8abbafbffe132a1808d6d0f24cae |
C2 Servers (3 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| 79.141.164.52 | ip | 4444 | TCP | sinkholed | RO |
| 185.234.218.151 | ip | 4444 | HTTPS | sinkholed | RU |
| 77.73.133.84 | ip | 443 | HTTPS | sinkholed | BG |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.