Branch was auto-updated.

This commit is contained in:
pyth0n1c
2022-07-27 13:16:40 -07:00
committed by GitHub
10 changed files with 33 additions and 0 deletions
@@ -35,6 +35,7 @@ tags:
- Malicious PowerShell
- Ingress Tool Transfer
- Log4Shell CVE-2021-44228
- DarkCrystal RAT
confidence: 70
context:
- Source:Endpoint
@@ -43,6 +43,7 @@ tags:
- Hermetic Wiper
- Industroyer2
- Azorult
- DarkCrystal RAT
automated_detection_testing: passed
confidence: 70
context:
@@ -44,6 +44,7 @@ tags:
- Malicious PowerShell
- NOBELIUM Group
- WhisperGate
- DarkCrystal RAT
asset_type: Endpoint
cis20:
- CIS 3
@@ -29,6 +29,7 @@ tags:
analytic_story:
- DHS Report TA18-074A
- HAFNIUM Group
- DarkCrystal RAT
asset_type: Endpoint
cis20:
- CIS 3
@@ -30,6 +30,7 @@ tags:
- Spearphishing Attachments
- Trickbot
- IcedID
- DarkCrystal RAT
confidence: 50
context:
- Source:Endpoint
@@ -30,6 +30,7 @@ references:
tags:
analytic_story:
- Trickbot
- DarkCrystal RAT
confidence: 80
context:
- Source:Endpoint
@@ -39,6 +39,7 @@ tags:
- WhisperGate
- Hermetic Wiper
- Industroyer2
- DarkCrystal RAT
automated_detection_testing: passed
confidence: 50
context:
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- Spearphishing Attachments
- DarkCrystal RAT
confidence: 100
context:
- Source:Endpoint
@@ -34,6 +34,7 @@ references:
tags:
analytic_story:
- Spearphishing Attachments
- DarkCrystal RAT
confidence: 100
context:
- Source:Endpoint
+24
View File
@@ -0,0 +1,24 @@
name: DarkCrystal RAT
id: 639e6006-0885-4847-9394-ddc2902629bf
version: 1
date: '2022-07-26'
author: Teoderick Contreras, Splunk
description: Leverage searches that allow you to detect and investigate unusual activities
that might relate to the DcRat malware including ddos, spawning more process, botnet c2 communication, defense evasion and etc.
The DcRat malware is known commercial backdoor that was first released in 2018. This tool was sold in underground forum and known to be one of the cheapest
commercial RATs.
DcRat is modular and bespoke plugin framework make it a very flexible option, helpful for a range of nefearious uses.
narrative: Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption
is the goal.
references:
- https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor
- https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat
tags:
analytic_story: DarkCrystal RAT
category:
- Malware
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection