Rewterz Threat Alert – SmokeLoader Malware – Active IOCs
February 2, 2022Rewterz Threat Alert – FormBook Malware – Active IOCs
February 2, 2022Rewterz Threat Alert – SmokeLoader Malware – Active IOCs
February 2, 2022Rewterz Threat Alert – FormBook Malware – Active IOCs
February 2, 2022Severity
High
Analysis Summary
Researchers have analyzed the Dark Crystal RAT capabilities and C2 message format. Unlike a real RAT server, this one does not have a user interface to allow the attacker to pick and launch commands. Instead, it has a pre-scripted command list that it sends to the RAT. When the server starts up, it uses the Python BaseHTTPServer to begin listening for incoming web requests. Incoming POST requests are assumed to hold a file that the RAT is uploading to the server; this server assumes all file uploads are screenshots and saves them to “screen.png”. The server sends four types of commands in sequence: first, it hides the desktop icons; then, it causes the string “Hello this is tech support” to be spoken; next, it displays a message box asking for a password; finally, it launches the Windows Calculator.
Impact
- Data Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- c46b14edc2d05dde4bc72d68935742d3
- 36ac15e3f4dbf43f664eeda2b1f55e5e
- 6a41552701b19f3575e881cc1b546be3
SHA-256
- 7c831f1840ecfafd13c7272d18f6139d485d7768bb03d9b0a09fcdfcc888ffe3
- 5c5cd9a05d9f32749d7be990318aa1a01a7c0a89e1b7a9e416633090070bcda0
- d5d30a5ef28b174b53eb85563522a5ad5936a7e311187313ee1784b2525e0073
SHA-1
- 618bba708cdfef0c8dfd5cca0475ea06c8a9a296
- cd6a637cf93544d5f5b06239132bdc64e75c1186
- 09582ab08c6dd8a373ae34d3a6adf6ebcb162b49
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.