Manuel Statik Analiz (LLM Okumali) — UnixStealer (a310Logger) | Tehdit: KRITIK
Dosya Kimligi
| SHA256 | 0d6f87aa1826205087affc7248276844f30892bd62b3f96ec75d02ceeb8cc5b4 |
|---|---|
| MB Etiketi | BlackGuard / a310Logger (MB) |
| Gercek Adi | UnixStealer (PDB'den) |
| Boyut | 303.617 byte |
| Platform | .NET (C#) |
Cleartext Discord Webhook C2 (KRITIK)
Discord Webhook (Exfiltrasyon): https://discord.com/api/webhooks/1447625794359922871/P8qhcUhcDIHUGD1nOnDph6_jiieLZ1Pb53vxaOsrZQ6tHyNyb7SSCwCX0JcaaQZucT3f Telegram Bot API (C2 Bildirim): https://api.telegram.org/bot[TOKEN] VimeWorld Dead Drop: https://api.vimeworld.ru/user/name/
UYARI: Discord webhook ve Telegram Bot API adresleri cleartext string olarak PE icinde tespit edilmistir. Bu adresler araciligiyla calinti veri dogrudan saldirganin Discord kanaline ve Telegram botuna iletilmektedir.
Gelistirici Izi (PDB Sizdirmasi)
C:\Users\brtig\OneDrive\Desktop\Src\UnixStealer\UnixStealer\obj\Release\UnixStealer.pdb Developer kullanici adi: brtig Proje adi: UnixStealer IDE: Visual Studio (Release Build)
Stealer Modulleri
| Modul | Hedef |
|---|---|
| UnixStealer.Chromium | Chrome, Brave, Edge — sifre/cookie/kredi karti |
| UnixStealer.Edge | Microsoft Edge veritabani |
| GrabTelegram | Telegram Desktop session |
| GetLocationSteam | Steam ssfn + hesap bilgisi |
| BitcoinCore | Bitcoin Core wallet.dat |
| WriteDiscord | Discord webhook exfiltrasyon modulu |
IOC
| SHA256 | 0d6f87aa1826205087affc7248276844f30892bd62b3f96ec75d02ceeb8cc5b4 |
|---|---|
| Discord Webhook | https://discord.com/api/webhooks/1447625794359922871/P8qhcUhcDIHUGD1nOnDph6_jiieLZ1Pb53vxaOsrZQ6tHyNyb7SSCwCX0JcaaQZucT3f |
| C2 | api.telegram.org (bot), api.vimeworld.ru (dead drop) |
| Developer | brtig (OneDrive/Desktop) |
UnixStealer — Malware Profile
UnixStealer (MB: a310Logger olarak etiketli), Discord webhook ve Telegram Bot API ile veri sızdiran .NET infostealerdir. Hedefler: Chrome/Edge/Brave sifreleri, Telegram Desktop session, Steam hesabi, Bitcoin Core wallet.dat. Gelistirici: brtig (PDB sizdirmasi).
Malware Type
Infostealer
Programming Language
C#/.NET
C2 Protocol
Discord Webhook/Telegram
Target Systems
Kuresel Bireysel
Capabilities & Behavior
Tarayıcı Kimlik Bilgileri
Çerez Hırsızlığı
Kripto Cüzdan Çalma
Sistem Bilgisi
Ekran Görüntüsü
FTP/SSH İstemci Şifreleri
E-posta İstemcisi Çalma
Veri Sızıntısı
IOC List (1 indicators)
IOC — UnixStealer
# SHA256
0d6f87aa1826205087affc7248276844f30892bd62b3f96ec75d02ceeb8cc5b4
| Type | Value | Note |
|---|---|---|
| sha256 | 0d6f87aa1826205087affc7248276844f30892bd62b3f96ec75d02ceeb8cc5b4 |
C2 Servers (3 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| api.vimeworld.ru | domain | 443 | HTTPS | active | — |
| api.telegram.org | domain | 443 | HTTPS | active | — |
| discord.com/api/webhooks/1447625794359922871/P8qhcUhcDIHUGD1nOnDph6_jiieLZ1Pb53vxaOsrZQ6tHyNyb7SSCwCX0JcaaQZucT3f | domain | — | HTTPS | inactive | — |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.