Statik Analiz — XWorm | YÜKSEK | CVSS: 7.5

Dosya

SHA256e6214ec3dc86e8aa709720e5fedaee79fd70b8dc0e25fcadd80ecdde63b50451
MD5a1ea911e1a52877455cd62ba133a675b
Dosyae6214ec3dc86e8aa709720e5fedaee79fd70b8dc0e25fcadd80ecdde63b50451.exe
Boyut4,166,656 byte
TürPE32+ executable for MS Windows 6.01 (GUI), x86-64, 8 sections
Stringler5,643

Bölümler

AdEntropi
.text6.23
.rdata6.42
.data3.96
.pdata4.96
.xdata1.78
.idata4.0
.reloc5.4
.symtab0.02

Import Tablosu

  • kernel32.dll

IOC

SHA256e6214ec3dc86e8aa709720e5fedaee79fd70b8dc0e25fcadd80ecdde63b50451
MD5a1ea911e1a52877455cd62ba133a675b
Domaingintmapnetfilereadopensyncpipestat.com, exec.in
BTC3ZbgzNTCgCow6uoRELrkntijTnGjw, 3zqwnz3AwEVPhPH1YxVvD5SpyJR3zT6PFY, 32H83gVkH7QwjfbWM8mAjJ7BFoRxjc, 3AJgwjRhQEQwhsG8RnWeFHpZCR5xDU, 35JwwvShAE7LWS5AnqXeFc55GRZ5nY
Mutexeq.sync.RWMutex, eq.sync.Mutex, sync.runtime_SemacquireMutex, runtime.mutex, poll.fdMutex
C2gintmapnetfilereadopensyncpipestat.com, exec.in

XWorm — Malware Profile

XWorm RAT .NET. Contract.exe is sozlesmesi. RecargarPanels Ispanyolca UI. panelActions plugin. Aggregate modül.

Malware Type
RAT
Programming Language
.NET C#
C2 Protocol
TCP
Target Systems
Windows

Technical Details

C# .NET, AES-128-CBC veya AES-256, TCP varsayilan port 7878, Anti-VM (GetSystemFirmwareTable), Anti-debug (FindWindow Olly/x64dbg), Webhook stealer, Clipper, HVNC, Remote Shell, Ransomware modulu

Capabilities & Behavior

Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması

IOC List (12 indicators)

IOC — XWorm
# 3ZbgzNTCgCow6uoRELrkntijTnGjw # 3zqwnz3AwEVPhPH1YxVvD5SpyJR3zT6PFY # 32H83gVkH7QwjfbWM8mAjJ7BFoRxjc # 3AJgwjRhQEQwhsG8RnWeFHpZCR5xDU # 35JwwvShAE7LWS5AnqXeFc55GRZ5nY # DOMAIN gintmapnetfilereadopensyncpipestat.com # DOMAIN exec.in # MUTEX eq.sync.RWMutex # MUTEX eq.sync.Mutex # MUTEX sync.runtime_SemacquireMutex # MUTEX runtime.mutex # MUTEX poll.fdMutex
TypeValueNote
3ZbgzNTCgCow6uoRELrkntijTnGjw BTC
3zqwnz3AwEVPhPH1YxVvD5SpyJR3zT6PFY BTC
32H83gVkH7QwjfbWM8mAjJ7BFoRxjc BTC
3AJgwjRhQEQwhsG8RnWeFHpZCR5xDU BTC
35JwwvShAE7LWS5AnqXeFc55GRZ5nY BTC
domain gintmapnetfilereadopensyncpipestat.com C2 domain
domain exec.in C2 domain
mutex eq.sync.RWMutex Mutex
mutex eq.sync.Mutex Mutex
mutex sync.runtime_SemacquireMutex Mutex
mutex runtime.mutex Mutex
mutex poll.fdMutex Mutex

C2 Servers (8 recorded servers for this family)

Address Type Port Protocol Status Country
system.io domain — TCP active —
eIL.ru domain — TCP active —
exec.in domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —
system.io domain — TCP active —

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
XWormmalwarestatik-analizIOC