Rewterz Threat Update – Conti Ransomware – Active IOCs
June 10, 2022Rewterz Threat Alert – DanaBot Trojan – Active IOCs
June 10, 2022Rewterz Threat Update – Conti Ransomware – Active IOCs
June 10, 2022Rewterz Threat Alert – DanaBot Trojan – Active IOCs
June 10, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
Data Theft
Exposure of Sensitive Data
Indicators of Compromise
MD5
- 513f2803b09639402a01f28a0dbdbdc4
- 4fc1d7482f5ef507946c57bebca8cecc
- 934fc324e634b13462a050770b5664d8
SHA-256
- 331a7ae480c3fcc7c3ea8e2ef33030e83c3d40fde9bdb3bd326b3e1d4488c9bb
- 3c7a2975470620f9075b736e679251750920c19729c00ec2fb47b91ea286deaf
- 5e192a8c1caa955cbec78a9a0a0daa949fed7767d365c2196dd043f7ce03d1dc
SHA-1
- d65c66f8c35b2643747dc2d35c7b684b787a99b6
- d6e7f56eebcf7d8e938625ae90a61eddb7dbe262
- ce20bf6b33d82b75b9abfa42ee25e2a62082c010
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.