Manuel Statik Analiz — SectopRAT/ArechClient2 | Tehdit: YUKSEK
Dosya Kimliği
| SHA256 | e6cf4d8f6bb3fcc4794028b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5 |
|---|---|
| Dosya Adı | puk3ta8cyv1.ps1 (obfüskülenmiş PowerShell) |
| Boyut | 794.028 byte |
| String Sayisi | 11.478 |
.su TLD C2 Domain
IOC: Sovyet .su TLD C2 — Rusça konuşan siber suçlu altyapısı!
gtLane6906.Su -- .su (Sovyet Birliği) TLD C2 sunucusu -- "gtLane" = gaming/betting platform taklidi? -- "6906" = port veya kampanya numarası
Base64 C2 Config
rMZIRioWL/vSU4ZR4ovGIr0BSkpzKLjI2wAmKnRQ06dOGGYESdMJyi/8P2/exvSzzEH5XqF0k3c2obp3... -- URL-safe olmayan Base64 → C2 server adres/port/şifreleme config
IOC
| SHA256 | e6cf4d8f6bb3fcc4794028b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5 |
|---|---|
| C2 | gtLane6906.Su |
SectopRAT2 — Malware Profile
SectopRAT2 (ArechClient2). PowerShell dropper. .su TLD C2. Base64 config. Remote access+credential steal.
Malware Type
RAT
Programming Language
C#/.NET
C2 Protocol
TCP/HTTPS
Target Systems
Kuresel
Capabilities & Behavior
Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması
IOC List (1 indicators)
IOC — SectopRAT2
# SHA256
e6cf4d8f6bb3fcc4794028b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5
| Type | Value | Note |
|---|---|---|
| sha256 | e6cf4d8f6bb3fcc4794028b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5 |
C2 Servers (1 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| gtLane6906.su | domain | 443 | HTTPS | inactive | — |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.