
Severity
High
Analysis Summary
Researchers have analyzed the Dark Crystal RAT capabilities and C2 message format. Unlike a real RAT server, this one does not have a user interface to allow the attacker to pick and launch commands. Instead, it has a pre-scripted command list that it sends to the RAT. When the server starts up, it uses the Python BaseHTTPServer to begin listening for incoming web requests. Incoming POST requests are assumed to hold a file that the RAT is uploading to the server; this server assumes all file uploads are screenshots and saves them to “screen.png”. The server sends four types of commands in sequence: first, it hides the desktop icons; then, it causes the string “Hello this is tech support” to be spoken; next, it displays a message box asking for a password; finally, it launches the Windows Calculator.
Impact
- Information Theft and Espionage
Indicators of Compromise
MD5
- a7a569051e04b4fe133cfb1648f2025f
- a8cc2c43020657165dad760ff7c3633a
- a4ee200a836ce43411b61a1256661445
- a1a138bef705e87cbd94f76d28a13c01
- a380057808b15f5dcf3bd53f6693d507
SHA-256
- 5e5254b2d8b943660e05ec94fc1d3a2c843e41bf78543c5e76310107686b7692
- b528e599bd80ddc3f74643ba69dff7c96c2b66bb669f974e0bb5473914e93432
- c258dfc5051bf9a05a2d52b76523b9454d0e6cffec006429c6dd43b9473b71ca
- c77f8c354591282a003118a78fd34981497e6575e68a2eda702cfc5c35f72258
- 2b5cb04ca42f0aa604ef6cf764ceb5102c7a3ef87096ba99cbf08606e08f8bc9
SHA-1
- 336ec74777537300ddf6c8692a5c16784df305c1
- 28aa8d73546a8149103be53be83a8fa7484e29a7
- bd9ea02ac1d14320fb8e0ec6441331a7e16e4b8e
- 8f5b407ef93e6d051b7bc7d0a39c1c9024b4c735
- 05bf82af4a67f2257986f28d43e850283ee1039a
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.