

Rewterz Threat Advisory – CVE-2022-22423 – IBM Common Cryptographic Architecture Vulnerability
September 27, 2022
Rewterz Threat Advisory – CVE-2022-34348 – IBM Partner Engagement Manager XML external Vulnerability
September 27, 2022
Rewterz Threat Advisory – CVE-2022-22423 – IBM Common Cryptographic Architecture Vulnerability
September 27, 2022
Rewterz Threat Advisory – CVE-2022-34348 – IBM Partner Engagement Manager XML external Vulnerability
September 27, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Data Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 1813103203337607b90a3a1e82147667
- 0732e5e635d83e53b483a32b7044e7a1
SHA-256
- 53bab521e261f13706ab05fa6820ef5a7e5e446c1bbdc7ff3a0b0f79349bdbf0
- 29b6b4ddecb81e06b9c4c25cff3a14931f0e492ca4a944c4bfcbd67e3dfb2ef1
SHA-1
- 7b3273e539dd8eb6e5f432bbe760b864c6e39257
- 9b4d70d9a3ff1ec6b78a2fa74847a8cd1012fa04
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.