Rewterz Threat Advisory – CVE-2022-40684 – Fortinet FortiOS and Fortinet FortiProxy Vulnerability
October 7, 2022Rewterz Threat Alert – Chaos Ransomware – Active IOCs
October 7, 2022Rewterz Threat Advisory – CVE-2022-40684 – Fortinet FortiOS and Fortinet FortiProxy Vulnerability
October 7, 2022Rewterz Threat Alert – Chaos Ransomware – Active IOCs
October 7, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Data Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 5a343516b2c56cea6e595dde2f92a143
- 4bb7565623661108ff31d4e724bd410d
- 47e0b51bfbf4b8bc22dc3f22ab7df28d
SHA-256
- 82e50ce98fa513afc6c5d8d4751f8235c7641000c8f3a88ebb7e8681325198c3
- 49daaced316b754055759ae06bac3cee2c2e28077db9288d047bf574d5e48849
- 4c0889d50d3d491f840511fa6bf6faaaf12d2a1d08b27a3535fba6733e7731de
SHA-1
- e013a23c4487c0eb4c287090efe3e0fd139c0572
- 0c4cb0784f4eb8f7f3aa945ac0cfcdbb03d8cbc6
- 14b9db854278063bb9ea4bfcf235168d7fd2610e
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.