Reverse engineering SuperBear RAT

2023-09-14 0x0v1

https://www.0x0v1.com/reverse-engineering-superbear-rat/

Thumbnail for Reverse engineering SuperBear RAT

SuperBear RAT was used against civil society targets and arrived through an AutoIT-based loader that hollowed explorer.exe, decrypted an embedded payload, and injected the PE into memory. The RAT created the mutex BEARLDR-EURJ-RHRHR, contacted hironchk[.]com over /id1, /id2, and /id3 paths, and checked C2 responses for the NdBrldr watermark. Supported commands included process and system discovery, upload of proc.db and sys.db, shell-command execution, and retrieval of base64-encoded DLL payloads for rundll32 execution. The analysis gives defenders concrete detection leads for AutoIT process hollowing, RWX memory in explorer.exe, the mutex, URI paths, and the upload endpoint /upload/upload.php.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 282e926eb90960a8a807dd0b9e8668e… 2023-08-31 2023-09-15
DOMAIN hironchk.com 2023-08-31 2023-09-15
HASH 5305b8969b33549b6bd4b68a3f9a2db… 2023-08-31 2023-09-14
HASH 454cfe3be695d0a387d7877c11d3b22… 2023-08-31 2023-09-14
URL https://syra.forumcommunity.net… 2023-08-31 2023-09-14
DOMAIN autoit-script.ru 2023-08-31 2023-09-14
DOMAIN syra.forumcommunity.net 2023-08-31 2023-09-14

Related Actors

Related Reports

« Back