Statik Analiz — NjRAT | YÜKSEK | CVSS: 7.5

Dosya

SHA256c23d69bfea7793258d6b77664fe5d32c8217246ddb9e827b69d6db03b917e3b7
MD5cb1724d06c8dfd5449741345bfd6ec94
Dosyac23d69bfea7793258d6b77664fe5d32c8217246ddb9e827b69d6db03b917e3b7.exe
Boyut40,158,208 byte
TürPE32 executable for MS Windows 4.00 (GUI), Intel i386, 8 sections
Stringler101,933

Bölümler

AdEntropi
CODE6.34
DATA1.12
BSS0.0
.idata3.48
.tls0.0
.rdata0.2
.reloc5.78
.rsrc7.97

Import Tablosu

  • kernel32.dll
  • kernel32.dll
  • shfolder.dll
  • shell32.dll

IOC

SHA256c23d69bfea7793258d6b77664fe5d32c8217246ddb9e827b69d6db03b917e3b7
MD5cb1724d06c8dfd5449741345bfd6ec94
IP17.4.0.0, 11.0.0.0, 4.0.0.0, 1.0.0.0, 17.0.0.0, 2.2.4.3
Domainsystem.io, system.net, microsoft.com, newtonsoft.com, globalsign.com
BTC32bMgmiwJE3sovgZyckCoqaLUebs, 1e4189245a58454f9acedc9da121f96c, 3TppMELEyitebaar22LvnxEpi5M, 35dasuDjXPQKsJY3zYSFzP7U7ei7GLr, 3414ea9e99ae48bb2aa84dc8889fd663
MutexCreateMutex, ReleaseMutex
C2system.io, system.net, microsoft.com, newtonsoft.com, globalsign.com

NjRAT — Malware Profile

njRAT Bladabindi. Spanish cotizacion lure. get_Panel1 C2 panel. MENA + Latin America targeting.

Malware Type
RAT
Programming Language
VB.NET
C2 Protocol
TCP (varsayilan port 1177)
Target Systems
Windows
Also Known As (AKA)
Bladabindi, H-Worm, houdini

Technical Details

TCP port 1177 (varsayilan), XOR tabanlı iletisim sifreleme, .NET Framework 2.0+, Mutex: {GUID}, Registry Run key persistence, Keylogger (GetAsyncKeyState), clipboard monitor, screenshot, remote shell, remote camera

Attribution / Threat Actor

Arap dilli siber suc topluluklari, en cok MENA (Orta Dogu ve Kuzey Afrika) bolgesindeki gruplar. Yasama savasi donemi Suriyeli gruplar tarafindan da kullanilmistir.

Capabilities & Behavior

Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması

IOC List (18 indicators)

IOC — NjRAT
# 32bMgmiwJE3sovgZyckCoqaLUebs # 1e4189245a58454f9acedc9da121f96c # 3TppMELEyitebaar22LvnxEpi5M # 35dasuDjXPQKsJY3zYSFzP7U7ei7GLr # 3414ea9e99ae48bb2aa84dc8889fd663 # IP 17.4.0.0 # IP 11.0.0.0 # IP 4.0.0.0 # IP 1.0.0.0 # IP 17.0.0.0 # IP 2.2.4.3 # DOMAIN system.io # DOMAIN system.net # DOMAIN microsoft.com # DOMAIN newtonsoft.com # DOMAIN globalsign.com # MUTEX CreateMutex # MUTEX ReleaseMutex
TypeValueNote
32bMgmiwJE3sovgZyckCoqaLUebs BTC
1e4189245a58454f9acedc9da121f96c BTC
3TppMELEyitebaar22LvnxEpi5M BTC
35dasuDjXPQKsJY3zYSFzP7U7ei7GLr BTC
3414ea9e99ae48bb2aa84dc8889fd663 BTC
ip 17.4.0.0 C2 aday
ip 11.0.0.0 C2 aday
ip 4.0.0.0 C2 aday
ip 1.0.0.0 C2 aday
ip 17.0.0.0 C2 aday
ip 2.2.4.3 C2 aday
domain system.io C2 domain
domain system.net C2 domain
domain microsoft.com C2 domain
domain newtonsoft.com C2 domain
domain globalsign.com C2 domain
mutex CreateMutex Mutex
mutex ReleaseMutex Mutex

C2 Servers (8 recorded servers for this family)

Address Type Port Protocol Status Country
system.io domain — TCP active —
microsoft.com domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
NjRATmalwarestatik-analizIOC