Rewterz Threat Alert – BumbleBee Malware – Active IOCs
September 20, 2022Rewterz Threat Alert – IcedID banking Trojan – Active IOCs
September 20, 2022Rewterz Threat Alert – BumbleBee Malware – Active IOCs
September 20, 2022Rewterz Threat Alert – IcedID banking Trojan – Active IOCs
September 20, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Data Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 1f6449bf99adac6a283e016227a1b6b5
- 0898e93604415bfd7b64225241dae9e1
- 20c07a8094977204113764aa3f959324
SHA-256
- 46c1b480004cbfe8b389b97546d69f41c344f2c52e3ea86a766a5cca1cb97024
- e8c1e19ca75697092076d76b0e55e40fdf368f3a7d1c2d96e2ba419a4bbdb1c0
- 0d64adb66067282d70ce69fb6f12badcea0e1615ba97ec323a6fa94a0649b36d
SHA-1
- b2142e82d2822b7f40adc1fc57e676dd07d41654
- 2026757d4e179fc832542e895736976c00cdb300
- 6972975e8d60ef167f764cb08955589d683c6b60
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.