Rewterz Threat Advisory – ICS: Hitachi RAID Manager Storage Replication Adapter Vulnerabilities
September 7, 2022Rewterz Threat Advisory – CVE-2022-20696 – Cisco SD-WAN vManage Software Vulnerability
September 8, 2022Rewterz Threat Advisory – ICS: Hitachi RAID Manager Storage Replication Adapter Vulnerabilities
September 7, 2022Rewterz Threat Advisory – CVE-2022-20696 – Cisco SD-WAN vManage Software Vulnerability
September 8, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
Data Theft
Exposure of Sensitive Data
Indicators of Compromise
MD5
- 194e50b51fffd24e507038cb6040e140
- 1b34602377fbe856bc2b46e7f230b3c0
SHA-256
- 1db44677c334016b1a8cd17708e03fb8fee2d0a746d85fb75a97662ed36f4c0f
- c28dda946198ea9e3f0088c9b26fa02bb4a8e5a59142ae48151dc55f6a649071
SHA-1
- 93d4fbab729c380c6d91700f237815780394e8e4
- d9ce4da54fe1102533b1111f73763007997bf5e3
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.