BianLian Ransomware -- 791KB, lbl.me C2, Veri Sızdırma + Fidye Çifte Baskı | Kritik
BianLian 791KB. lbl.me C2 domain. Android bankacılık trojanından fidye yazılımına evrim. Çifte baskı gasp.
Analyses de menaces complètes, IOC et rapports de recherche sur RAT, Infostealer, Backdoor et autres familles de malwares.
BlackGuard 517KB. 22+ kripto cüzdan + tarayıcı credential hedefi. $200/ay dark web MaaS. .NET C# stealer.
BianLian 791KB. lbl.me C2 domain. Android bankacılık trojanından fidye yazılımına evrim. Çifte baskı gasp.
ErbiumStealer 224KB Setup.exe. 1DR8Q756yz + 3oCZ6W7H BTC. IsDebuggerPresent anti-debug. 2022 MaaS stealer.
Vultur 2.1MB APK. ActionBar.Su, ActionMode.Su, AppCompat.Me - AndroidX sinif adi .su/.me TLD obfukas. VNC ekran kayit.
FormBook 287KB dstq.exe. Chrome/IE credential toplama. Rastgele ad dropper. MaaS stealer 2016.
TrickBot 396KB 55ryoipjfdr.exe rastgele adlı dropper. Finansal bankacilık trojanı. GetTickCount anti-debug.
Squirrelwaffle 541KB e-posta thread hijacking loader. IsDebuggerPresent. Qakbot+Cobalt Strike dropper. 2021.
Tofsee 78KB spam botnet. mail.ru + yahoo.com spam hedefi. C:\Users\Bruno\Desktop\file.exe PDB. NtQueryInformationToken.
GootLoader 87MB. "Legal_Case_Management_Guide" ZIP SEO zehirleme. Meşru arama sonucu taklidi. JS loader.
Makop 233KB. Kore dili "전산자료 보존요청서" evrak muhafaza belgesi lure. GetTickCount anti-debug. 2020.
LockBit 3 (bl3.exe) 994KB. "Enter password for the encrypted file" parola korumalı variant. Anti-debug.
RoyalRansom 2.5MB Linux ELF. royal2xthig3ou5h...onion C2. AES-NI + SEED + OpenSSL. BTC 1qwDEq+37Qi9e.
BlackMatter 515KB run-as-admin.exe. mojobiden.com + paymenthacks.com Cobalt Strike C2. supp24yy6a66hw...onion.
WannaCry 2.4MB. Kill switch iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com. BTC 117oSxuc+11KVs795Y4. EternalBlue.
Industroyer2 37KB. ICS/SCADA endüstriyel kontrol sistemi wiper. Ukrayna enerji altyapisi sabotaji. Sandworm/GRU APT.
WhisperGate 544KB Ukrayna wiper. gnidaerhT.me, eroC.me, emitnuR.me - .NET namespace tersine cevirme obfuskas. Rus APT.
Bandook 48KB PDF. "Confirmar Transferencia lista" Portekizce banka transferi lure. Çok platform backdoor.
Yashma/Chaos 289KB svchost.exe. encryptionAesRsa + checkdeleteShadowCopies. BTC 1163hSV1jJ. .wallet dosya hedefi.
MedusaLocker 444KB. Yashma ransomware builder v1.2 PDB. medusaxko7j...onion Tor C2. BTC cüzdanlar. 100+ hedef uzantı.
TrueBot 413KB. NtQuerySystemInformation anti-sandbox. DC2_USERS domain controller C2 config. Silence Group.