Rewterz Threat Alert – RedLine Stealer – Active IOCs
September 15, 2022Rewterz Threat Alert – SmokeLoader Malware – Active IOCs
September 16, 2022Rewterz Threat Alert – RedLine Stealer – Active IOCs
September 15, 2022Rewterz Threat Alert – SmokeLoader Malware – Active IOCs
September 16, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Data Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 376f4a99cc6bc6b39fed16430bcb57a3
- 36d335dac984a522421bc91964725fb2
- 3031cd4e1f880f65d88764c449c855f
SHA-256
- da0fab9ff04f3e8e0a9f8eb12eeafacc8328074cd7313d3f8a28ea33c340335b
- c32d9f3e68923d40027dad0bb525795d5aa605b039e5b480a7d713c6b8d44594
- c60aed547fed1a45b7c356d7f795663b200b26b6f37ca052cfc6f06315fcef00
SHA-1
- 00035aafbdb137acc02ea0b3fb340249929fb7ad
- 5cefbce23c88328fe51590e9c7d6a0e34c05e941
- f7a4c0324b53633aeb7a818285f8c72facfa061b
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.