Rewterz Threat Alert – Active Dridex Banking Trojan Spam Campaign Targeting Users Amid Black Friday Sales
November 26, 2021Rewterz Threat Alert – Agent Tesla Malware – Active IOCs
November 26, 2021Rewterz Threat Alert – Active Dridex Banking Trojan Spam Campaign Targeting Users Amid Black Friday Sales
November 26, 2021Rewterz Threat Alert – Agent Tesla Malware – Active IOCs
November 26, 2021Severity
High
Analysis Summary
Researchers have analyzed the Dark Crystal RAT capabilities and C2 message format. Unlike a real RAT server, this one does not have a user interface to allow the attacker to pick and launch commands. Instead, it has a pre-scripted command list that it sends to the RAT. When the server starts up, it uses the Python BaseHTTPServer to begin listening for incoming web requests. Incoming POST requests are assumed to hold a file that the RAT is uploading to the server; this server assumes all file uploads are screenshots and saves them to “screen.png”. The server sends four types of commands in sequence: first, it hides the desktop icons; then, it causes the string “Hello this is tech support” to be spoken; next, it displays a message box asking for a password; finally, it launches the Windows Calculator.
Impact
- Data Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- b268d67eb783433947b188973ece669e
- b20f834f26b4e298cc1a7b0d039c85e5
SHA-256
- 33e1234fdd620e4ad0831096c07355a1cf3798338c4b032f5cc41201c8db0b5e
- 76f6aebb88e2677a88ac980baf774444c52738760290902d9f45d774c3ed377e
SHA-1
- f808139ca55e88e26f400398fdd7b2588cc6f143
- 48402207d0bbce92dd4da0e98a389f980375e165
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.