Dosya Kimligi
| SHA256 | c559ae3589ef6275ab17974827435d17215a4f81b35da976a98299021addcc93 |
|---|---|
| Orijinal Ad | 440b4ef096504461be38b21b0ec74e57.exe |
| Install Adi | WindowsServices.exe |
| Boyut | 32.256 byte |
| Dil | VB.NET (.NET Framework 2.0) |
| Packer | Yok (normal entropi: 5.61) |
C2 Sunucusu & Ag Iletisimi
| Adres | Tip | Protokol | Tespit Yontemi |
|---|---|---|---|
jun88.now | DDNS Domain | TCP | Strings — gomunlu konfigurasyon |
Baglanti Anahtari (Key/ID): f217d66ad40ee1c58064dc08d8ad14a8
NjRAT varsayilan portlari: 1177, 5552, 7777
Persistence (Kalicilik)
| Yontem | Deger |
|---|---|
| Registry Run Key | HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsServices |
| Dropped Dosya | C:\Users\[USER]\AppData\Roaming\WindowsServices.exe |
| Firewall Bypass | netsh firewall add allowedprogram ... ENABLE |
Yetenekler
- Keylogger — GetAsyncKeyState, GetKeyboardLayout, GetKeyboardState, MapVirtualKey, ToUnicodeEx
- Screenshot / Ekran Goruntuleme — CopyFromScreen, Bitmap, Graphics, PixelFormat
- Webcam Yakalama — avicap32.dll, capGetDriverDescriptionA, capCreateCaptureWindow
- USB Yayilimi — USB_SP modulu, GetLogicalDrives
- Uzaktan Komut Calistirma — Shell, Execute, cmd.exe
- Dosya Yoneticisi — ReadAllBytes, WriteAllBytes, Download, FileStream
- AV Tespiti — Select * From AntiVirusProduct (WMI SecurityCenter2)
- Remote Desktop (Uzak Erisim) — TcpClient, NetworkStream, Socket
- Process Manager — GetProcessesByName, GetProcessById
Anti-Analiz Teknikleri
- Anti-Debug — NtSetInformationProcess (ThreadHideFromDebugger)
- VM Tespiti — VBoxService, VGAuthService string kontrolu
- Sandbox/Arac Tespiti: procexp, SbieCtrl (Sandboxie), SpyTheSpy, wireshark, apateDNS, IPBlocker, TiGeR-Firewall, smsniff, exeinfoPE, NetSnifferCs, Sandboxie Control, processhacker
- Analiz Araci Tespiti: dnSpy, CodeReflect, Reflector, ILSpy (debugger tespit)
String Temelli Bulgular
Kritik Stringler: [C2 HOST] jun88.now [INSTALL] WindowsServices.exe [REGISTRY] Software\Microsoft\Windows\CurrentVersion\Run [KEY] f217d66ad40ee1c58064dc08d8ad14a8 [B64-1] Zmx5ODgua3Jk => (decode edilemedi) [B64-2] Y262SUCZ4UJJ => (decode edilemedi) [FW-BYPASS] netsh firewall add allowedprogram ... ENABLE [DROPPED] WindowsServices.exe (Stub.exe referansi) [AV-QUERY] Select * From AntiVirusProduct [VMCHECK] VBoxService, VGAuthService [DEBUGGER] dnSpy, ILSpy, processhacker, SbieCtrl
Teknik Ozet
Bu ornek, VB.NET ile yazilmis NjRAT (Bladabindi) ailesi Remote Access Trojan'idir.
32KB boyutuyla kucuk ama kapsamli fonksiyonlara sahip: keylogger, ekran goruntuleme,
webcam yakalama, USB yayilimi, dosya yoneticisi, uzaktan komut yurütme. C2
iletisimi TCP uzerinden jun88.now adresine baglaniyor. Registry Run
key ile kalicilik sagliyor, netsh firewall ile kendini Windows guvenlik duvarina
ekliyor. Analiz araclarina (Sandboxie, ILSpy, Wireshark, x64dbg, processhacker)
ve sanallaStirma ortamlarina (VirtualBox, VMware) karsi koruma iceriyor.
NjRAT — Malware Profile
njRAT Bladabindi. Spanish cotizacion lure. get_Panel1 C2 panel. MENA + Latin America targeting.
Technical Details
TCP port 1177 (varsayilan), XOR tabanlı iletisim sifreleme, .NET Framework 2.0+, Mutex: {GUID}, Registry Run key persistence, Keylogger (GetAsyncKeyState), clipboard monitor, screenshot, remote shell, remote camera
Attribution / Threat Actor
Arap dilli siber suc topluluklari, en cok MENA (Orta Dogu ve Kuzey Afrika) bolgesindeki gruplar. Yasama savasi donemi Suriyeli gruplar tarafindan da kullanilmistir.
Capabilities & Behavior
IOC List (6 indicators)
# SHA256
c559ae3589ef6275ab17974827435d17215a4f81b35da976a98299021addcc93
# MD5
440b4ef096504461be38b21b0ec74e57
# DOMAIN
jun88.now
# DOMAIN
fly88.krd
# REGISTRY
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
# FILEPATH
C:\Users\AppData\Roaming\WindowsServices.exe
| Type | Value | Note |
|---|---|---|
| sha256 | c559ae3589ef6275ab17974827435d17215a4f81b35da976a98299021addcc93 | |
| md5 | 440b4ef096504461be38b21b0ec74e57 | |
| domain | jun88.now | |
| domain | fly88.krd | |
| registry | HKCU\Software\Microsoft\Windows\CurrentVersion\Run | |
| filepath | C:\Users\AppData\Roaming\WindowsServices.exe |
C2 Servers (8 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| system.io | domain | — | TCP | active | — |
| microsoft.com | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
| system.io | domain | — | TCP | active | — |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.