Rewterz Threat Alert – STOP/DJVU Ransomware – Active IOCs
September 23, 2022Rewterz Threat Alert – Chaos Ransomware – Active IOCs
September 23, 2022Rewterz Threat Alert – STOP/DJVU Ransomware – Active IOCs
September 23, 2022Rewterz Threat Alert – Chaos Ransomware – Active IOCs
September 23, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Data Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- e4e07f55a04050c162b53a7e3c6bd44d
- 41e024325a7e7113980d2c0e503ed169
- 152fc3939962d6e1e572f00b33daf7b6
SHA-256
- 4f2efddecf32090500cebdfd8bea11d04511e72786b00186af04b68f5ecfacd1
- dadc049078b6792d44dfa72dcbfbce66f10ff6cb43f6bb4720c01b5ed52216cc
- f1aceefbbb01466f19ac3e421082e81bf0c90e2d758665bb8124b5ebf14b5743
SHA-1
- 1cf436767aad6dcbd297628fb830d49d6e0bb3c6
- 3f8d672876162bf967eed62e610593cbcc3c38d2
- 25a7bebb0bdce7657fc563949befbf52021b5ea0
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.