Rewterz Threat Alert – Novel Malware Discovered Targeting VMware ESXi Servers
September 30, 2022Rewterz Threat Alert – LokiBot Malware – Active IOCs
September 30, 2022Rewterz Threat Alert – Novel Malware Discovered Targeting VMware ESXi Servers
September 30, 2022Rewterz Threat Alert – LokiBot Malware – Active IOCs
September 30, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Data Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 2c417c97427a41c7a256ebd6aebde68f
- 227b53ad332668d5ea0f637f6ebb033d
- 2a097b6528b1d69d02c3b35a9209ecc4
SHA-256
- 9758de188c5acef7f5a4559316024433fbd96ef2df914161a3d814d0f22e2718
- 4656f2f8d8f2bc07bb122f1016517cbfac7a5622daefa5dfd434febd1a21b669
- ba921e5bd4687eec051d4e646756bb2930ec900abf061b94761d6944f906afba
SHA-1
- d9836f4ec36f8dd0d1e6d86b2910ff77a2f96a72
- 627acc717c4db9215c0705054708b4c9d2c14a73
- 47b4d6dcb3314e0bb75b99c305dadb36ed2ce27b
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.