Rewterz Threat Advisory – Multiple Apache OFBiz Vulnerabilities
September 5, 2022Rewterz Threat Advisory – CVE-2022-38764 – Trend Micro HouseCall Vulnerability
September 5, 2022Rewterz Threat Advisory – Multiple Apache OFBiz Vulnerabilities
September 5, 2022Rewterz Threat Advisory – CVE-2022-38764 – Trend Micro HouseCall Vulnerability
September 5, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
Data Theft
Exposure of Sensitive Data
Indicators of Compromise
MD5
- 093c7ecf0cca000498d7d9ee8e185ce7
- 1c316e7438b5053692a71428119b66ae
- 6d69ed217f98e2534bf7c63b227bfe33
SHA-256
- 4dfb188031331f1d4adfc0d47daa0f3e2a2ab64d49dc807b3aa1be46070be365
- 441b57017c4771be4690b30a4b28b54fa930766676f0e17858fb8cc2d2429b6a
- b8743ee8177658a9d4699df002b2efe14925eede3a480fe30d6a7fe024f814cc
SHA-1
- d390fbd1425b8f3f40f98c9a8bffbbf9010632ff
- 41010c2465987fdb2d7e2fb7b12869bf76371411
- 90f1529728c0fad37bbbd04916edb58b13751876
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.