Analysis of Delta Charlie Attack Malware
2017-08-23 • USCISA •
https://www.us-cert.gov/sites/default/files/publications/MAR-10132963.pdf
Attachments
MAR-10132963.pdf (172 KB)
US-CERT analyzed three files associated with DeltaCharlie attack malware that combine backdoor command-and-control capability with DDoS attack functions. One Windows executable installs a packet driver and a service named netplug, uses the mutex \Global\NetplugDiscovery0.7, and loads a configuration resource that derives the C2 address 202.126.90.89 from a hard-coded IP value. The bot can download and execute files, update modules, change configuration, self-delete through msvcrt.bat, and start or stop attacks. Supported attack modes include NTP, DNS, and carrier-grade NAT UDP-flood activity, with local logs recording installation, C2 connection, and attack execution events.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ncr.com | 2017-08-23 | 2018-08-28 |
| HASH | a4fc300b72266ccce1977f93b1bca3b5 | 2017-08-23 | 2017-08-23 |
| HASH | 8a4c040480f15d80c171884c0404408… | 2017-08-23 | 2017-08-23 |
| HASH | 6dd10b0e9a62a4943665e32d36c02b9f | 2017-08-23 | 2017-08-23 |
| HASH | 584ac94142f0b7c0df3d0adde6e661ed | 2017-08-23 | 2017-08-23 |
| HASH | b164ba5e5734c469839292ede4d5c04… | 2017-08-23 | 2017-08-23 |
| HASH | 1bdda8ad01a81904160d4aaff5028678 | 2017-08-23 | 2017-08-23 |
| HASH | 11eab7228491af5ac109f58055c8f94f | 2017-08-23 | 2017-08-23 |
| HASH | 8f4fc2e10b6ec15a01e0af24529040dd | 2017-08-23 | 2017-08-23 |
| HASH | 8a4d0080f19580e97c884d00454b75f0 | 2017-08-23 | 2017-08-23 |
| HASH | 3fdf856b6fbcb23e7c3372a3f53ce26… | 2017-08-23 | 2017-08-23 |
| HASH | 6a5356bedf23ccecac180cd887c15de8 | 2017-08-23 | 2017-08-23 |
| HASH | 219125d84f95e9ec104a49383da7b991 | 2017-08-23 | 2017-08-23 |
| HASH | b994d715f522732213ea03cb2013a469 | 2017-08-23 | 2017-08-23 |
| HASH | 1f21185303b7992d6ef54b23e816d48… | 2017-08-23 | 2017-08-23 |
| HASH | 5d29dfe2ea9ca8da3ff7a14fb20c5e86 | 2017-08-23 | 2017-08-23 |
| HASH | 72d9f7da3d7eb917a18954668399ce67 | 2017-08-23 | 2017-08-23 |
| HASH | af59deeeff5d5f41ecdd092b80536d25 | 2017-08-23 | 2017-08-23 |
| DOMAIN | corp.ncr.com | 2017-08-23 | 2017-08-23 |
| IPv4 | 202.126.90.89 | 2017-08-23 | 2017-08-23 |
| IPv4 | 153.68.198.14 | 2017-08-23 | 2017-08-23 |