SHA-256: 7213e78737d5364647a6b0f8a777f133f9e60cb33bb0507d12154faca2c9da3c

Static Analysis Report — 7213e78737d5

SHA-256: 7213e78737d5364647a6b0f8a777f133f9e60cb33bb0507d12154faca2c9da3c
Family: sky-jamaica (alias skywalker)
Confidence: high
Analysis type: static-only (CAPE skipped — no Windows guest)


1. Build / RE

  • Format: PE32+ (x64) .NET CIL assembly — .NET Framework 4.x (v4.0.30319) ^[file.txt] ^[rabin2-info.txt]
  • Compiled: Tue May 19 12:00:44 2026; MVID F8E628D6012D442D90C37847F99CC80A1 ^[rabin2-info.txt]
  • PDB: C:\Source\1\ClientDll\obj\x64\Release\sky_jamaica_noexport.pdb ^[strings.txt:5248]
  • Signing: Unsigned (signed: false) ^[rabin2-info.txt]
  • Packing / obfuscation: None. ~3,969 functions with full unobfuscated symbols (Client.*, Shared.*, <>c__DisplayClass*) ^[rabin2-info.txt] ^[capa.txt]
  • Toolchain: Microsoft Visual Studio / MSBuild (standard C#)
  • Version string: REV05 ^[strings.txt:5039]
  • Code quality: Professional modular architecture: packet-serialized C2 (Shared.Packets.*, Shared.Network.PacketSerializer), humanized input simulation (Bezier curves, Gaussian delays, Fitts' law stepping), and extensive configuration structs.

2. Deploy / ATT&CK

All TTPs inferred from static analysis.

Technique Evidence
T1056.001 — Keylogging KeyboardHook.Hook → SetWindowsHookEx (WH_KEYBOARD_LL); KeyloggerLoop, SendKeyloggerData ^[strings.txt]
T1113 — Screen Capture MagnificationCapture via MagInitialize / MagSetWindowSource; fallback BitBlt via CaptureScreenBitBlt ^[strings.txt]
T1115 — Clipboard Data ClipboardMonitorStart, OnClipboardChanged, ReadAndSendClipboard ^[strings.txt]
T1213 — Data from Info Repositories HarvestOutlookWebContacts, HarvestGmailContacts, RunWhatsAppHarvest — contact harvesting via CDP ^[strings.txt]
T1027 — Obfuscated Files GZip + AES payload encryption for C2 traffic ^[capa.txt]
T1497 — Sandbox Evasion ApplyAntiVM, DetectDevTools, ApplyHideProcess, ApplyTokens, anti-VM strings targeting QEMU, VMware, VirtualBox, Xen ^[strings.txt] ^[capa.txt]
T1564.003 — Hidden Window MakeSilentInstanceInvisible, MakeSilentWppInvisible, MakeSilentOlkInvisible — layered window manipulation for hidden CDP browser instances ^[strings.txt]
T1547.009 — Shortcut Modification PatchAllShortcuts, PatchSingleShortcut, PatchShortcutsInDir inject --remote-debugging-port into browser shortcuts ^[strings.txt]
T1047 — WMI AntivirusWmi, FirewallWmi queries for security software enumeration ^[strings.txt]
T1010 — App Window Discovery EnumWindows, GetWindowThreadProcessId, CheckBrowserWindows, CdpEnumWindowsProc ^[strings.txt]
T1082 — System Info Discovery Exfiltrates 50+ fields via SystemDiagPacket: Windows build, DPI, monitors, RAM, CPU, AV, firewall, Defender exclusions, .NET version, Office 365 version, network adapters, battery, power plan ^[strings.txt]
T1070.004 — File Deletion CleanupFilesOnExit, CleanSentItems, CleanDeletedItems ^[strings.txt]

C2 & Comms

  • Raw TCP + WebSocket (WsSend, WsRecv, WsSendRaw, WsRecvRaw) ^[strings.txt]
  • HTTP GET/POST (HttpGet, HttpPost, DownloadString) ^[strings.txt]
  • Optional Tor/SOCKS5: TorEnabled, ConnectViaSocks5, DownloadFileViaSocks5 ^[strings.txt]
  • Backup server list (BackupServerItem) with dead-drop resolution (TryFetchDeadDrop) ^[strings.txt]

Persistence & Evasion

  • Hosts file patch: PatchHostsFile redirects banking domains ^[strings.txt]
  • Extension sideload: BuildExtensionFiles, PackCrx3, WriteExtensionPolicy, CalcExtensionId — constructs CRX3 and registers via policy registry ^[strings.txt]
  • Scheduled tasks: SCHTASKS_EXE referenced for task-based persistence ^[strings.txt]
  • Registry: Extension policy writes, GPU rendering keys, Edge quick-search keys ^[strings.txt]
  • Single-instance mutex: SingleInstanceMutex, MUTEX_NAME ^[strings.txt]

Fraud Overlay / Hole System

  • ShowBlockScreen, ShowBlockScreenWithHtml, ShowTempBlockForm create topmost blocking windows ^[strings.txt]
  • CreateHoleFormInternal, SetFormHoleWithOptions cut a "hole" through the overlay so the victim can interact with the real bank page while the attacker controls surrounding UI ^[strings.txt]
  • HoleUrlMonitorLoop polls the browser address bar to trigger overlays on targeted banking URLs ^[strings.txt]
  • Mouse/keyboard hooks (StartBlockingHooks, SetWindowsHookEx) redirect or suppress input during overlay display ^[strings.txt]

Banking Targets (CASA_* constants)

BBVA, Banorte, Santander, Banamex, City, Binance, Paxful, Cripto ^[strings.txt]

Crypto Wallet Replacement

DetectCryptoType, GetCryptoReplacement, CheckAndReplaceHash — replaces clipboard or on-screen cryptocurrency addresses with attacker-controlled ones (BTC, ETH ERC-20, USDT ERC-20, USDT TRC-20, DOGE, BCH, LTC) ^[strings.txt]

CDP Browser Abuse

The malware's defining feature. Patches browser shortcuts to inject --remote-debugging-port, then drives hidden Chromium instances via CDP WebSocket:

  • Cookie injection/extraction (CdpInjectCookies, ExtractCookiesViaChromelevator, ParseChromelevatorCookies) ^[strings.txt]
  • Page navigation (NavigateViaCdp, CdpReloadPage) ^[strings.txt]
  • Contact harvesting (ExecuteOutlookCdp, ExecuteGmailCdp, ExecuteWhatsAppCdp) ^[strings.txt]
  • Message relay via victim's authenticated sessions (RunWhatsAppSend, RunWhatsAppSendByNameWithAttach) ^[strings.txt]
  • DevTools detection (StartDetectDevTools, StopDetectDevTools) ^[strings.txt]

Provenance:

  • strings.txt — 5,248 lines, 99 KB of unobfuscated .NET symbols and literals
  • capa.txt — 250 capability matches (Mandiant flare-capa v7)
  • rabin2-info.txt — radare2 binary header summary
  • file.txt — PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly
  • dynamic-analysis.md — CAPE skipped (no Windows guest)