

Rewterz Threat Advisory – ICS: Multiple Siemens Teamcenter Vulnerabilities
August 15, 2022
Rewterz Threat Alert – Agent Tesla Malware – Active IOCs
August 15, 2022
Rewterz Threat Advisory – ICS: Multiple Siemens Teamcenter Vulnerabilities
August 15, 2022
Rewterz Threat Alert – Agent Tesla Malware – Active IOCs
August 15, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Unauthorized Remote Access
- Keylogging
- Information Theft
- Password Theft
Indicators of Compromise
MD5
- a982ffbfdec51fdac3ac7bf56e0d884d
- a7ed0410d6b5e16ab5fce129d34ffa8e
- abb092a8123f20be29e580955c2fcdbe
SHA-256
- eb908d8bd0618c6cc8c38674c1e6dbf0e6fb4994e49cac2e00e689defff90e84
- 2e0be091675065564b4f68ef1b3835b29f00b706f96e6f4cd8b28669be7a1d6f
- 02a1c09b32def97f736b6eb185f54b7253e4c41288538def8f1c9e3b4dc1e963
SHA-1
- 04d029c22e2e5a5ff043e7e224bd295b8082b358
- 1f6d4b107617207fc406775157486d3e4d62c559
- 91e91bd29945ef5284337e441462cb3e5931efb0
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.