Dosya Kimligi
| SHA256 | ea096956563a39486203fb29d70cde41840da92d1da5d48e8f4fd72b3ceafc1f |
|---|---|
| Dosya Adi | sysmon.exe (Sysinternals Sysmon kamuflaj) |
| Boyut | 401.920 byte |
| String Sayisi | 2.599 |
Kamuflaj Stratejisi
sysmon.exe ismi, Microsoft Sysinternals'in legitim guvenlik aracinin adini taklit eder. Sistem yoneticileri ve AV'ler bu isme guvenerek islemin analiz edilmesini atlayabilir.
Hedefler
chrome, chrome.dll, chrome_elf.dll, chrome.exe -- Google Chrome kullanici veritabani ve cookie hedefleniyor
PrivateLoader Hakkinda
PrivateLoader, 2021 yilindan beri aktif olan bir Pay-Per-Install (PPI) loader hizmetidir. Underground piyasada satilan bu hizmet, musterilerin istedikleri payload'lari kurban sistemlerine yukleme kapasitesi saglar. Hedef sistemde ilk kez calistirildiktan sonra sifrelenmis C2 ile iletisim kurar ve ikinci asama payload (RedLine, Raccoon, Vidar, vb.) indirir.
IOC
| SHA256 | ea096956563a39486203fb29d70cde41840da92d1da5d48e8f4fd72b3ceafc1f |
|---|---|
| Kamuflaj | sysmon.exe (Sysinternals taklidı) |
| Hedef | Chrome DLL |
PrivateLoader — Malware Profile
PrivateLoader/PrivateLdr. sysmon.exe Sysinternals fake. cJSON C library. Chrome browser targeting.
Technical Details
Varyanta gore C/C#/VBS/PS1, anti-analysis (VM/debugger check), persistence (Registry/Task Scheduler/Startup folder), payload decryption ve injection (shellcode/PE), fileless execution teknikleri
Capabilities & Behavior
IOC List (1 indicators)
# SHA256
ea096956563a39486203fb29d70cde41840da92d1da5d48e8f4fd72b3ceafc1f
| Type | Value | Note |
|---|---|---|
| sha256 | ea096956563a39486203fb29d70cde41840da92d1da5d48e8f4fd72b3ceafc1f |
C2 Servers (4 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| 45.142.213.167 | ip | 80 | HTTP | inactive | RU |
| 87.251.64.160 | ip | 80 | HTTP | inactive | NL |
| known2.me | domain | 443 | HTTPS | inactive | — |
| 45.138.74.63 | ip | 443 | HTTPS | sinkholed | RU |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.