

Rewterz Threat Advisory – CVE-2022-45378 – Apache SOAP Vulnerability
November 16, 2022
Rewterz Threat Advisory – CVE-2022-45136 – Apache Jena SDB Vulnerability
November 16, 2022
Rewterz Threat Advisory – CVE-2022-45378 – Apache SOAP Vulnerability
November 16, 2022
Rewterz Threat Advisory – CVE-2022-45136 – Apache Jena SDB Vulnerability
November 16, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Unauthorized Remote Access
- Keylogging
- Information Theft
- Password Theft
Indicators of Compromise
MD5
- e4d36e28d3b449eb13e123edba90a359
- f2f63fb441e54b56e81107f0da947e42
- 384e6c5f2bc25d6c8f7adb6231dca5ce
SHA-256
- da836408b89e756bd33aed58103d85199671e6fa41ded4d2247bf189b29c6f14
- f67b08acb8ae930c53b21771a17f4e28b528eb31a70781cbdce31fef6c97b00a
- 75782c9790e9f65f921fc34cd2c5bf0826d845adeaaeb21873e09c5e914ce15a
SHA-1
- 086866e70769b2069d5fcb8ab8906695c28dd2a9
- f1f8e1b7a05f8bb4a6badca7e45c3442aa3f2a4e
- 02d7b808b6b8277059c70028536f1c48e97c9227
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.