Rewterz Threat Alert – Hidden Cobra Latest Activity
March 2, 2020Rewterz Threat Alert – Active Scans for Apache Tomcat Ghostcat Vulnerability Detected, Patch Now
March 3, 2020Rewterz Threat Alert – Hidden Cobra Latest Activity
March 2, 2020Rewterz Threat Alert – Active Scans for Apache Tomcat Ghostcat Vulnerability Detected, Patch Now
March 3, 2020Severity
High
Analysis Summary
A new campaign is found distributing the ProClient RAT that has advanced capabilities of a cyber espionage.
This RAT is written in .NET, and is called ProClient (named after some namespaces present inside), with advanced features for spying and checking the victim, as well as for theft of credentials.The structure of the malware turned out to be rather simple, favoring its reverse engineering. In the sample detected, the final payload – a DLL containing ProClient – is protected by aseries of packers (including CyaX), the latter of which also has the task of executing the entry-point method by passing it the configuration.
Impact
- Credential Theft
- Spying
- Unauthorized Remote Access
- Cyber Espionage
Indicators of Compromise
Hostname
- bc[.]iensar[.]com
- srv1[.]cn-uinquetex[.]com
MD5
- b139021611bbd7b5260b01ff39825e06
- acea0de197c9dc33ead49fb3ee74c75d
SHA-256
- ff9d6a35aeeb1207104071c683edede7ac571d515bef53b174d736ae8a2db3cf
- 8f4a84541272fb3e27b37c5a03840e634aa4cafb6e48bd5a8540e8f40db248ce
SHA1
- 48b32a1eb417495f27cacecc6850d8bd40f9e6c7
- 2cb791373c7be82d0cae6190704df9a4504e2c83
Remediation
- Block the threat indicators at their respective controls.
- Do not download files from untrusted sources.
- Conduct employee awareness programs against social engineering and phishing.