

Rewterz Threat Update – Microsoft Exchange Zero-Day Actively Exploited In The Wild
October 2, 2022
Rewterz Threat Alert –DangerousPassword APT Group – Active IOCs
October 2, 2022
Rewterz Threat Update – Microsoft Exchange Zero-Day Actively Exploited In The Wild
October 2, 2022
Rewterz Threat Alert –DangerousPassword APT Group – Active IOCs
October 2, 2022Severity
High
Analysis Summary
DCRat – a Russian backdoor, was initially introduced in 2018, but rebuilt and relaunched a year later. The DCRat backdoor appears to be the product of a single threat actor who goes online with the pseudonyms of “boldenis44,” “crystalcoder,” and Кодер (“Coder”).
DCRat is one of the cheapest commercial RATs. For a two-month membership, the price starts at 500 RUB (less than 5 GBP/US$6), and it periodically drops even cheaper during special offers. This is written in .NET and features a modular structure, allowing affiliates to create their own plugins using DCRat Studio, a dedicated integrated development environment (IDE).
The malware’s modular architecture allows it to be extended for a variety of nefarious objectives, including surveillance, reconnaissance, data theft, DDoS attacks, and arbitrary code execution.
The DCRat consists of three parts:
- A stealer/client executable
- The command-and-control (C2) endpoint/ interface is a single PHP page
- An administrator tool
The malware is still in development, the author announces any news and updates through a dedicated Telegram channel with about 3k users updated with any news and changes.
Impact
- Data Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 01498f6bd1d1b79cc6a152dc5a625d12
- 02b7395a500cba20e53c0be24c2a5834
- 0d2e08a91156af301ccebb8b48f467ad
SHA-256
- eccaec76c66960ba7245ac0b0d60c5f79ed52603a8333da79668ef4e78f42059
- 99cb3e6404b5415de7a6300f1ad678fe95b0027ea7ebd04d005489172afbad85
- d6e59815c0f787f63a9a47677b12a225e719b8779db8265f10673d0bb991b5f9
SHA-1
- 9590d8a136011ef8f831277c9d98aae8fba1e06a
- 6b7ea7bdb8ce465e06c7fc13b7a76251e48187b4
- 9ec45df299be2c14ea64135e40a4026a5f47c7f4
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.