Rewterz Threat Update – France Hospital Center Hospitalier Sud Francilien Hit By A Ransomware Attack
August 25, 2022Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
August 26, 2022Rewterz Threat Update – France Hospital Center Hospitalier Sud Francilien Hit By A Ransomware Attack
August 25, 2022Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
August 26, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
Data Theft
Exposure of Sensitive Data
Indicators of Compromise
MD5
- c0918be21cdc6aacfe3e36dcaaf1b9ae
- b84441d968c6751a01357a86b2e85ee7
- b5a1f3ca86e16095ab457dd3ecae5165
SHA-256
- 490b5a1b1b77f410e6cbb7a3deabd7f7aeb08dfd94c38aeb0b11152fc79d1459
- 0aeb2381432c215c345c58a46f7a51fa816c2d02634b41f54e8fcaae731ccc17
- 0e845dc526ed2bc4252311fde8630f1aec9bb8e92e2ebbdb1bbc25c9c29391c4
SHA-1
- 3bdd091ae84f37eb82fbe8b3d8a2769d061443d5
- 3b23ffd646ccd56386d4d00fc66bd7c276e296c2
- 51f359e4f5d57083107d9887d579438b05d4debe
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.