Manuel Statik Analiz (LLM Okumali) — NjRAT / Bladabindi | Tehdit: HIGH

Dosya Kimligi

SHA256c559ae3589ef6275ab17974827435d17215a4f81b35da976a98299021addcc93
Orijinal Ad440b4ef096504461be38b21b0ec74e57.exe
Install AdiWindowsServices.exe
Boyut32.256 byte
DilVB.NET (.NET Framework 2.0)
PackerYok (normal entropi: 5.61)

C2 Sunucusu & Ag Iletisimi

AdresTipProtokolTespit Yontemi
jun88.nowDDNS DomainTCPStrings — gomunlu konfigurasyon

Baglanti Anahtari (Key/ID): f217d66ad40ee1c58064dc08d8ad14a8

NjRAT varsayilan portlari: 1177, 5552, 7777

Persistence (Kalicilik)

YontemDeger
Registry Run KeyHKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsServices
Dropped DosyaC:\Users\[USER]\AppData\Roaming\WindowsServices.exe
Firewall Bypassnetsh firewall add allowedprogram ... ENABLE

Yetenekler

  • Keylogger — GetAsyncKeyState, GetKeyboardLayout, GetKeyboardState, MapVirtualKey, ToUnicodeEx
  • Screenshot / Ekran Goruntuleme — CopyFromScreen, Bitmap, Graphics, PixelFormat
  • Webcam Yakalama — avicap32.dll, capGetDriverDescriptionA, capCreateCaptureWindow
  • USB Yayilimi — USB_SP modulu, GetLogicalDrives
  • Uzaktan Komut Calistirma — Shell, Execute, cmd.exe
  • Dosya Yoneticisi — ReadAllBytes, WriteAllBytes, Download, FileStream
  • AV Tespiti — Select * From AntiVirusProduct (WMI SecurityCenter2)
  • Remote Desktop (Uzak Erisim) — TcpClient, NetworkStream, Socket
  • Process Manager — GetProcessesByName, GetProcessById

Anti-Analiz Teknikleri

  • Anti-Debug — NtSetInformationProcess (ThreadHideFromDebugger)
  • VM Tespiti — VBoxService, VGAuthService string kontrolu
  • Sandbox/Arac Tespiti: procexp, SbieCtrl (Sandboxie), SpyTheSpy, wireshark, apateDNS, IPBlocker, TiGeR-Firewall, smsniff, exeinfoPE, NetSnifferCs, Sandboxie Control, processhacker
  • Analiz Araci Tespiti: dnSpy, CodeReflect, Reflector, ILSpy (debugger tespit)

String Temelli Bulgular

Kritik Stringler:
  [C2 HOST]   jun88.now
  [INSTALL]   WindowsServices.exe
  [REGISTRY]  Software\Microsoft\Windows\CurrentVersion\Run
  [KEY]       f217d66ad40ee1c58064dc08d8ad14a8
  [B64-1]     Zmx5ODgua3Jk  =>  (decode edilemedi)
  [B64-2]     Y262SUCZ4UJJ  =>  (decode edilemedi)
  [FW-BYPASS] netsh firewall add allowedprogram ... ENABLE
  [DROPPED]   WindowsServices.exe (Stub.exe referansi)
  [AV-QUERY]  Select * From AntiVirusProduct
  [VMCHECK]   VBoxService, VGAuthService
  [DEBUGGER]  dnSpy, ILSpy, processhacker, SbieCtrl

Teknik Ozet

Bu ornek, VB.NET ile yazilmis NjRAT (Bladabindi) ailesi Remote Access Trojan'idir. 32KB boyutuyla kucuk ama kapsamli fonksiyonlara sahip: keylogger, ekran goruntuleme, webcam yakalama, USB yayilimi, dosya yoneticisi, uzaktan komut yurütme. C2 iletisimi TCP uzerinden jun88.now adresine baglaniyor. Registry Run key ile kalicilik sagliyor, netsh firewall ile kendini Windows guvenlik duvarina ekliyor. Analiz araclarina (Sandboxie, ILSpy, Wireshark, x64dbg, processhacker) ve sanallaStirma ortamlarina (VirtualBox, VMware) karsi koruma iceriyor.

NjRAT — Malware Profile

njRAT Bladabindi. Spanish cotizacion lure. get_Panel1 C2 panel. MENA + Latin America targeting.

Malware Type
RAT
Programming Language
VB.NET
C2 Protocol
TCP (varsayilan port 1177)
Target Systems
Windows
Also Known As (AKA)
Bladabindi, H-Worm, houdini

Technical Details

TCP port 1177 (varsayilan), XOR tabanlı iletisim sifreleme, .NET Framework 2.0+, Mutex: {GUID}, Registry Run key persistence, Keylogger (GetAsyncKeyState), clipboard monitor, screenshot, remote shell, remote camera

Attribution / Threat Actor

Arap dilli siber suc topluluklari, en cok MENA (Orta Dogu ve Kuzey Afrika) bolgesindeki gruplar. Yasama savasi donemi Suriyeli gruplar tarafindan da kullanilmistir.

Capabilities & Behavior

Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması

IOC List (6 indicators)

IOC — NjRAT
# SHA256 c559ae3589ef6275ab17974827435d17215a4f81b35da976a98299021addcc93 # MD5 440b4ef096504461be38b21b0ec74e57 # DOMAIN jun88.now # DOMAIN fly88.krd # REGISTRY HKCU\Software\Microsoft\Windows\CurrentVersion\Run # FILEPATH C:\Users\AppData\Roaming\WindowsServices.exe
TypeValueNote
sha256 c559ae3589ef6275ab17974827435d17215a4f81b35da976a98299021addcc93
md5 440b4ef096504461be38b21b0ec74e57
domain jun88.now
domain fly88.krd
registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run
filepath C:\Users\AppData\Roaming\WindowsServices.exe

C2 Servers (8 recorded servers for this family)

Address Type Port Protocol Status Country
system.io domain — TCP active —
microsoft.com domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
njratbladabindiratkeyloggerscreenshotwebcamc2tcpvbnetstatik-analizmanuel