Rewterz
Rewterz Threat Alert – DJVU Ransomware – Active IOCs
December 29, 2021
Rewterz
Rewterz Threat Alert – NJRAT – Active IOCs
December 30, 2021

Rewterz Threat Alert – Dark Crystal RAT – Active IOCs

Severity

High

Analysis Summary

Researchers have analyzed the Dark Crystal RAT capabilities and C2 message format. Unlike a real RAT server, this one does not have a user interface to allow the attacker to pick and launch commands. Instead, it has a pre-scripted command list that it sends to the RAT. When the server starts up, it uses the Python BaseHTTPServer to begin listening for incoming web requests. Incoming POST requests are assumed to hold a file that the RAT is uploading to the server; this server assumes all file uploads are screenshots and saves them to “screen.png”. The server sends four types of commands in sequence: first, it hides the desktop icons; then, it causes the string “Hello this is tech support” to be spoken; next, it displays a message box asking for a password; finally, it launches the Windows Calculator.

Impact

  • Data Theft
  • Exposure of Sensitive Data

Indicators of Compromise

MD5

  • 3ec7b6de56d6aa927b9f1cac6e72518d
  • 4ed7fa930b105e4a07ba9014253bb781
  • a710687bd248c76a7155412960601904

SHA-256

  • 5e9f048e53c7833bbd9662c266ba75e8cf5e5af500627a0c2630697cf47ad92c
  • 1978a133fc8bcbba7fac230cfff5c2fc6ac2681e9f84df4231bfc056bf2cd91f
  • 5ed80f3e0c9d4c92b05864fafffd410becd10235c0cb34cd1ac46090dc83f293

SHA-1

  • 6efccbdd1d4518a7e429eff492410887b985c7af
  • 066bb9de3a55f5571efa7b5b83a9f8355239c284
  • 0c39b589e82b345c701d78c38802536de9a6bd7c

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.