Rewterz
Rewterz Threat Alert – Wanna Cryptor aka WannaCry Ransomware- Active IOCs
January 2, 2023
Rewterz
Rewterz Threat Alert – Phobos Ransomware – Active IOCs
January 2, 2023

Rewterz Threat Alert – DarkCrystal RAT (DCRat) – Active IOCs

Severity

High

Analysis Summary

DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”). 

DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).

The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.

The DCRat consists of three parts:

  • A stealer/client executable
  • The command-and-control (C2) endpoint/ interface is a single PHP page
  • An administrator tool

The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.

Impact

  • Unauthorized Remote Access
  • Keylogging
  • Information Theft
  • Password Theft

Indicators of Compromise

MD5

  • c6b62cf78028c333e2adaaaf993c193d
  • c38955f79b23fe751718121fefcd7695

SHA-256

  • 50e30c6649c8f63ecf147a1b1a7831f34c7827f46b7ad76a1f9b089c6cacfdb9
  • 6ae816ec46ae1900c7a334251d27c93c9b793ee77b521b5dfbb9b81c64d21c10

SHA-1

  • c92da4915d8365e25148ac77184e7913c7181969
  • 59ae09cee276abee4803260a53a6f40e6a160f65

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.