High
A new campaign is found distributing the ProClient RAT that has advanced capabilities of a cyber espionage.
This RAT is written in .NET, and is called ProClient (named after some namespaces present inside), with advanced features for spying and checking the victim, as well as for theft of credentials.The structure of the malware turned out to be rather simple, favoring its reverse engineering. In the sample detected, the final payload – a DLL containing ProClient – is protected by aseries of packers (including CyaX), the latter of which also has the task of executing the entry-point method by passing it the configuration.
Hostname
MD5
SHA-256
SHA1