Derin Analiz — FalseXmrig RAT | Tehdit: YUKSEK
Dosya Kimligi
| SHA256 | a3fa75fe9b9c0ca9ccdc85ae6733024cbc64c545031aad9150f03fed9335850a |
|---|---|
| Dosya | xmrig_x86_truncated.elf (yanlis isim: aslinda UPX PE32) |
| Boyut | 354,816 byte (PE32 GUI x86, UPX packed) |
| Entropi | 7.419 (packed) |
| Entrypoint | FAKE (sahte) |
| Sections | UPX0 (zero length), UPX1 (self-modifying) |
NtUnmapViewOfSection: Process Hollowing
PROCESS HOLLOWING: NtUnmapViewOfSection tespit edildi -- xmrig kisves altinda RAT!
NtUnmapViewOfSection\n\n-- NtUnmapViewOfSection: hedef prosesi bos birak, payload inject et\n-- Klasik process hollowing adimi:\n 1. CreateProcess SUSPENDED ile hedef proses ac\n 2. NtUnmapViewOfSection ile bellek unmap et\n 3. VirtualAllocEx ile yeni alan ayir\n 4. WriteProcessMemory ile payload yaz\n 5. SetThreadContext ile EIP degistir\n 6. ResumeThread ile calistir\n-- "xmrig_x86_truncated.elf" ismi: xmrig madenci taklidi kamuflaj
AVICAP32.DLL: Webcam Erisimi
AVICAP32.DLL -> capGetDriverDescriptionA\n\n-- AVICAP32: Windows Video Capture kutuphanesi\n-- capGetDriverDescriptionA: sistemdeki kamera suruculerini listele\n-- Webcam akisi icin yapi:\n capCreateCaptureWindow -> capDriverConnect -> capGrabFrame\n-- Amac: kurban makinesinin kamera goruntusunu gizlice kayit et\n-- Gdiplus.dll GdipFree: screenshot kapasitesi (GDI+ goruntu isle)
FtpPutFileA: FTP Veri Sizintisi
FtpPutFileA (wininet.dll)\nURLDownloadToFileA\n\n-- FtpPutFileA: ele gecirilen dosyalari FTP sunucusuna yukle\n-- URLDownloadToFileA: C2 sunucusundan ek payload indir\n-- Iki yonlu: indirme (payload al) + yukleme (veri gonder)\n-- FTP: silinmesi zor log birakmaz, AV imzayi gecebilir\n-- cmd.exe entegrasyonu: ShellExecuteA ile sistem komutlari
IOC
| SHA256 | a3fa75fe9b9c0ca9ccdc85ae6733024cbc64c545031aad9150f03fed9335850a |
|---|---|
| Packer | UPX (fake entrypoint) |
| Hollowing | NtUnmapViewOfSection |
| Webcam | AVICAP32.DLL capGetDriverDescriptionA |
| Exfil | FtpPutFileA (FTP upload) |
| Download | URLDownloadToFileA (payload) |
FalseXmrigRAT — Malware Profile
UPX-packed PE32 RAT disguised as xmrig crypto miner (.elf extension fake). NtUnmapViewOfSection process hollowing. AVICAP32 webcam capture. GDI+ screenshot. FtpPutFileA FTP data exfiltration. URLDownloadToFileA second-stage download. ShellExecuteA CMD execution.
Malware Type
RAT
Programming Language
C/C++
C2 Protocol
FTP/HTTP
Target Systems
Kuresel
Capabilities & Behavior
Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması
IOC List (1 indicators)
IOC — FalseXmrigRAT
# SHA256
a3fa75fe9b9c0ca9ccdc85ae6733024cbc64c545031aad9150f03fed9335850a
| Type | Value | Note |
|---|---|---|
| sha256 | a3fa75fe9b9c0ca9ccdc85ae6733024cbc64c545031aad9150f03fed9335850a |