Rewterz Threat Alert – Mirai Botnet – Active IOCs
September 25, 2022Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
September 25, 2022Rewterz Threat Alert – Mirai Botnet – Active IOCs
September 25, 2022Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
September 25, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Data Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 11f790ade80bc83204d10e4c7cf2f957
- 0428077f1eee71b4f540a484fdf1d3f1
- 23ad9152f3a6d184571cc783570acfb3
SHA-256
- f7d4d0c674f3dc9ad0b2bc85b65c1cd2eea9e25d67c86790e30b0ff3452fb82a
- d60a44786cf95b2796e1d4d12f8f13c3e8497f6aeb654be950bfc412f737ab45
- 6a3089c2b2f867954b3bc96c9c5938a5fffe909d446a5596538e816bcd948d0c
SHA-1
- f59adc7146d76222816821ec5d9e11fbfc501f9e
- e86085a6ef4d7f2449bf207588d33ed4be1a3143
- 1cfe06ef207bd6467cbb585f8e3a9760e2989b97
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.