Statik Analiz — XWorm | YÜKSEK | CVSS: 7.5

Dosya

SHA256bbd9b8056f45e78c75028f31179a89b92e5d75e179ee2fcde1e3d57ee2264538
MD5ed8e74e0eb69487ed7a105ac6c05a82b
Dosyabbd9b8056f45e78c75028f31179a89b92e5d75e179ee2fcde1e3d57ee2264538.exe
Boyut4,164,608 byte
TürPE32+ executable for MS Windows 6.01 (GUI), x86-64, 8 sections
Stringler5,634

Bölümler

AdEntropi
.text6.23
.rdata6.42
.data3.96
.pdata5.22
.xdata1.78
.idata3.94
.reloc5.41
.symtab0.02

Import Tablosu

  • kernel32.dll

IOC

SHA256bbd9b8056f45e78c75028f31179a89b92e5d75e179ee2fcde1e3d57ee2264538
MD5ed8e74e0eb69487ed7a105ac6c05a82b
Domaingintmapnetfilereadopensyncpipestat.com, exec.in
BTC1TLcV1Ycxus4gBBuuQSuj31LEP, 18KMR198Bus2cNBuumPuv3NfQP, 3Juv4J8YiRceoBDWYNR96S5koStyW5, 383zqKiMBus3oNBuvkouz3MDAP, 3x2RDhhqRtBzcC2FjmdcziYNHiCGdwZ1jsh
Mutexeq.sync.RWMutex, eq.sync.Mutex, sync.runtime_SemacquireMutex, runtime.mutex, poll.fdMutex
C2gintmapnetfilereadopensyncpipestat.com, exec.in

XWorm — Malware Profile

XWorm RAT .NET. Contract.exe is sozlesmesi. RecargarPanels Ispanyolca UI. panelActions plugin. Aggregate modül.

Malware Type
RAT
Programming Language
.NET C#
C2 Protocol
TCP
Target Systems
Windows

Technical Details

C# .NET, AES-128-CBC veya AES-256, TCP varsayilan port 7878, Anti-VM (GetSystemFirmwareTable), Anti-debug (FindWindow Olly/x64dbg), Webhook stealer, Clipper, HVNC, Remote Shell, Ransomware modulu

Capabilities & Behavior

Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması

IOC List (12 indicators)

IOC — XWorm
# 1TLcV1Ycxus4gBBuuQSuj31LEP # 18KMR198Bus2cNBuumPuv3NfQP # 3Juv4J8YiRceoBDWYNR96S5koStyW5 # 383zqKiMBus3oNBuvkouz3MDAP # 3x2RDhhqRtBzcC2FjmdcziYNHiCGdwZ1jsh # DOMAIN gintmapnetfilereadopensyncpipestat.com # DOMAIN exec.in # MUTEX eq.sync.RWMutex # MUTEX eq.sync.Mutex # MUTEX sync.runtime_SemacquireMutex # MUTEX runtime.mutex # MUTEX poll.fdMutex
TypeValueNote
1TLcV1Ycxus4gBBuuQSuj31LEP BTC
18KMR198Bus2cNBuumPuv3NfQP BTC
3Juv4J8YiRceoBDWYNR96S5koStyW5 BTC
383zqKiMBus3oNBuvkouz3MDAP BTC
3x2RDhhqRtBzcC2FjmdcziYNHiCGdwZ1jsh BTC
domain gintmapnetfilereadopensyncpipestat.com C2 domain
domain exec.in C2 domain
mutex eq.sync.RWMutex Mutex
mutex eq.sync.Mutex Mutex
mutex sync.runtime_SemacquireMutex Mutex
mutex runtime.mutex Mutex
mutex poll.fdMutex Mutex

C2 Servers (8 recorded servers for this family)

Address Type Port Protocol Status Country
system.io domain — TCP active —
eIL.ru domain — TCP active —
exec.in domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
XWormmalwarestatik-analizIOC