mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
5.0 KiB
5.0 KiB
title, last_modified_at, toc, toc_label, tags
| title | last_modified_at | toc | toc_label | tags | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| DarkCrystal RAT | 2022-07-26 | true |
|
Try in Splunk Security Cloud{: .btn .btn--success}
Description
Leverage searches that allow you to detect and investigate unusual activities that might relate to the DcRat malware including ddos, spawning more process, botnet c2 communication, defense evasion and etc. The DcRat malware is known commercial backdoor that was first released in 2018. This tool was sold in underground forum and known to be one of the cheapest commercial RATs. DcRat is modular and bespoke plugin framework make it a very flexible option, helpful for a range of nefearious uses.
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2022-07-26
- Author: Teoderick Contreras, Splunk
- ID: 639e6006-0885-4847-9394-ddc2902629bf
Narrative
Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption is the goal.
Detections
Reference
- https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor
- https://malpedia.caad.fkie.fraunhofer.de/details/win.dcrat
source | version: 1