Reverse engineering SuperBear RAT

2023-08-31 Ovi

https://0x0v1.com/posts/superbear/superbear/

Thumbnail for Reverse engineering SuperBear RAT

The reverse-engineering write-up details the SuperBear RAT used in a campaign against civil society groups, focusing on the AutoIT stage and the injected Windows payload. The AutoIT script was compiled and packed, then used process hollowing to inject a decrypted PE into explorer.exe, where analysts found the C2-related strings. SuperBear created the mutex “BEARLDR-EURJ-RHRHR,” connected to hironchk[.]com over URI paths such as /id1, /id2, and /id3, and checked returned HTML for the “NdBrldr” watermark. Its commands supported process and system-information exfiltration via files under C:\Users\Public\Documents, shell-command download and execution, and Base64-encoded DLL retrieval followed by rundll32 execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 282e926eb90960a8a807dd0b9e8668e… 2023-08-31 2023-09-15
DOMAIN hironchk.com 2023-08-31 2023-09-15
HASH 5305b8969b33549b6bd4b68a3f9a2db… 2023-08-31 2023-09-14
HASH 454cfe3be695d0a387d7877c11d3b22… 2023-08-31 2023-09-14
URL https://syra.forumcommunity.net… 2023-08-31 2023-09-14
DOMAIN autoit-script.ru 2023-08-31 2023-09-14
DOMAIN syra.forumcommunity.net 2023-08-31 2023-09-14

Related Actors

Related Reports

« Back