Analysis of Delta Charlie Attack Malware

2017-08-23 USCISA

https://www.us-cert.gov/sites/default/files/publications/MAR-10132963.pdf

Attachments

MAR-10132963.pdf (172 KB)

Thumbnail for Analysis of Delta Charlie Attack Malware

US-CERT analyzed three files associated with DeltaCharlie attack malware that combine backdoor command-and-control capability with DDoS attack functions. One Windows executable installs a packet driver and a service named netplug, uses the mutex \Global\NetplugDiscovery0.7, and loads a configuration resource that derives the C2 address 202.126.90.89 from a hard-coded IP value. The bot can download and execute files, update modules, change configuration, self-delete through msvcrt.bat, and start or stop attacks. Supported attack modes include NTP, DNS, and carrier-grade NAT UDP-flood activity, with local logs recording installation, C2 connection, and attack execution events.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ncr.com 2017-08-23 2018-08-28
HASH a4fc300b72266ccce1977f93b1bca3b5 2017-08-23 2017-08-23
HASH 8a4c040480f15d80c171884c0404408… 2017-08-23 2017-08-23
HASH 6dd10b0e9a62a4943665e32d36c02b9f 2017-08-23 2017-08-23
HASH 584ac94142f0b7c0df3d0adde6e661ed 2017-08-23 2017-08-23
HASH b164ba5e5734c469839292ede4d5c04… 2017-08-23 2017-08-23
HASH 1bdda8ad01a81904160d4aaff5028678 2017-08-23 2017-08-23
HASH 11eab7228491af5ac109f58055c8f94f 2017-08-23 2017-08-23
HASH 8f4fc2e10b6ec15a01e0af24529040dd 2017-08-23 2017-08-23
HASH 8a4d0080f19580e97c884d00454b75f0 2017-08-23 2017-08-23
HASH 3fdf856b6fbcb23e7c3372a3f53ce26… 2017-08-23 2017-08-23
HASH 6a5356bedf23ccecac180cd887c15de8 2017-08-23 2017-08-23
HASH 219125d84f95e9ec104a49383da7b991 2017-08-23 2017-08-23
HASH b994d715f522732213ea03cb2013a469 2017-08-23 2017-08-23
HASH 1f21185303b7992d6ef54b23e816d48… 2017-08-23 2017-08-23
HASH 5d29dfe2ea9ca8da3ff7a14fb20c5e86 2017-08-23 2017-08-23
HASH 72d9f7da3d7eb917a18954668399ce67 2017-08-23 2017-08-23
HASH af59deeeff5d5f41ecdd092b80536d25 2017-08-23 2017-08-23
DOMAIN corp.ncr.com 2017-08-23 2017-08-23
IPv4 202.126.90.89 2017-08-23 2017-08-23
IPv4 153.68.198.14 2017-08-23 2017-08-23
« Back