Reverse engineering SuperBear RAT
2023-09-14 • 0x0v1 •
SuperBear RAT was used against civil society targets and arrived through an AutoIT-based loader that hollowed explorer.exe, decrypted an embedded payload, and injected the PE into memory. The RAT created the mutex BEARLDR-EURJ-RHRHR, contacted hironchk[.]com over /id1, /id2, and /id3 paths, and checked C2 responses for the NdBrldr watermark. Supported commands included process and system discovery, upload of proc.db and sys.db, shell-command execution, and retrieval of base64-encoded DLL payloads for rundll32 execution. The analysis gives defenders concrete detection leads for AutoIT process hollowing, RWX memory in explorer.exe, the mutex, URI paths, and the upload endpoint /upload/upload.php.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 282e926eb90960a8a807dd0b9e8668e… | 2023-08-31 | 2023-09-15 |
| DOMAIN | hironchk.com | 2023-08-31 | 2023-09-15 |
| HASH | 5305b8969b33549b6bd4b68a3f9a2db… | 2023-08-31 | 2023-09-14 |
| HASH | 454cfe3be695d0a387d7877c11d3b22… | 2023-08-31 | 2023-09-14 |
| URL | https://syra.forumcommunity.net… | 2023-08-31 | 2023-09-14 |
| DOMAIN | autoit-script.ru | 2023-08-31 | 2023-09-14 |
| DOMAIN | syra.forumcommunity.net | 2023-08-31 | 2023-09-14 |