General
-
Target
DCRatBuild.exe
-
Size
1.9MB
-
Sample
240701-az1tja1arh
-
MD5
469d978118f1a8de4a1a5bb33bc81a93
-
SHA1
295ce921008c39f1f3f0ac1e1ccde97ad5c0f12e
-
SHA256
5b8f511ca8a386c382cd23b305d295ae406a9aae2392f7543de21d5d67c44ced
-
SHA512
7d71ac9b37d6ca74339e6a7b8b08a72ba72b8f7fedce1ed6d80703eafb31dd4d5e70de4118cf719292cb3de9cb5f84b27b79492b95e890df143e0c5c295cbc44
-
SSDEEP
49152:UbA307leyidFZE7vBekGuQ/kp129bxWEvd0:UbIyh70kF/p12A
Behavioral task
behavioral1
Sample
DCRatBuild.exe
Resource
win11-20240508-en
Malware Config
Targets
-
-
Target
DCRatBuild.exe
-
Size
1.9MB
-
MD5
469d978118f1a8de4a1a5bb33bc81a93
-
SHA1
295ce921008c39f1f3f0ac1e1ccde97ad5c0f12e
-
SHA256
5b8f511ca8a386c382cd23b305d295ae406a9aae2392f7543de21d5d67c44ced
-
SHA512
7d71ac9b37d6ca74339e6a7b8b08a72ba72b8f7fedce1ed6d80703eafb31dd4d5e70de4118cf719292cb3de9cb5f84b27b79492b95e890df143e0c5c295cbc44
-
SSDEEP
49152:UbA307leyidFZE7vBekGuQ/kp129bxWEvd0:UbIyh70kF/p12A
Score10/10-
DcRat
DarkCrystal(DC) is a new .NET RAT active since June 2019 capable of loading additional plugins.
-
Disables Task Manager via registry modification
-
Executes dropped EXE
-
Drops file in System32 directory
-