Rewterz Threat Alert – AsyncRAT – Active IOCs
February 27, 2023Rewterz Threat Alert – RedLine Stealer – Active IOCs
February 27, 2023Rewterz Threat Alert – AsyncRAT – Active IOCs
February 27, 2023Rewterz Threat Alert – RedLine Stealer – Active IOCs
February 27, 2023Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Unauthorized Remote Access
- Keylogging
- Information Theft
- Password Theft
Indicators of Compromise
MD5
3026138d1adee4d2a9f7b2b1d307ba75
274aa684c9366ec70a90510906cb823f
SHA-256
12439f78eedb2588923e7d8d48ded871d0cf7de5be265e25957d2eb8833b34c9
a1612631fe4d0f6d85f1293ac62776c6134c326a7ee368eacca23ce9a09afa49
SHA-1
14bdf0ba46b0f9c41b69b9f2c37ee73a231733af
bf38b69febebff5c50c61441c7a0f25b9e7ef8f8
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.