Manuel Statik Analiz (LLM Okumali) — PrivateLoader | Tehdit: YUKSEK

Dosya Kimligi

SHA256ea096956563a39486203fb29d70cde41840da92d1da5d48e8f4fd72b3ceafc1f
Dosya Adisysmon.exe (Sysinternals Sysmon kamuflaj)
Boyut401.920 byte
String Sayisi2.599

Kamuflaj Stratejisi

LOTL (Living off the Land): sysmon.exe ismi, Microsoft Sysinternals'in legitim guvenlik aracinin adini taklit eder. Sistem yoneticileri ve AV'ler bu isme guvenerek islemin analiz edilmesini atlayabilir.

Hedefler

chrome, chrome.dll, chrome_elf.dll, chrome.exe
-- Google Chrome kullanici veritabani ve cookie hedefleniyor

PrivateLoader Hakkinda

PrivateLoader, 2021 yilindan beri aktif olan bir Pay-Per-Install (PPI) loader hizmetidir. Underground piyasada satilan bu hizmet, musterilerin istedikleri payload'lari kurban sistemlerine yukleme kapasitesi saglar. Hedef sistemde ilk kez calistirildiktan sonra sifrelenmis C2 ile iletisim kurar ve ikinci asama payload (RedLine, Raccoon, Vidar, vb.) indirir.

IOC

SHA256ea096956563a39486203fb29d70cde41840da92d1da5d48e8f4fd72b3ceafc1f
Kamuflajsysmon.exe (Sysinternals taklidı)
HedefChrome DLL

PrivateLoader — Malware Profile

PrivateLoader/PrivateLdr. sysmon.exe Sysinternals fake. cJSON C library. Chrome browser targeting.

Malware Type
Loader
Programming Language
C++
C2 Protocol
HTTP
Target Systems
Windows

Technical Details

Varyanta gore C/C#/VBS/PS1, anti-analysis (VM/debugger check), persistence (Registry/Task Scheduler/Startup folder), payload decryption ve injection (shellcode/PE), fileless execution teknikleri

Capabilities & Behavior

Payload İndirme
Süreç Enjeksiyonu
Modüler Mimari
Kimlik Bilgisi Hırsızlığı
Yanal Hareket
Kalıcılık
Anti-VM/Sandbox
İkincil Payload Dağıtımı

IOC List (1 indicators)

IOC — PrivateLoader
# SHA256 ea096956563a39486203fb29d70cde41840da92d1da5d48e8f4fd72b3ceafc1f
TypeValueNote
sha256 ea096956563a39486203fb29d70cde41840da92d1da5d48e8f4fd72b3ceafc1f

C2 Servers (4 recorded servers for this family)

Address Type Port Protocol Status Country
45.142.213.167 ip 80 HTTP inactive RU
87.251.64.160 ip 80 HTTP inactive NL
known2.me domain 443 HTTPS inactive —
45.138.74.63 ip 443 HTTPS sinkholed RU

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
privateloadersysmonchromelotlpay-per-installloaderkamuflaj