Reverse engineering SuperBear RAT
2023-08-31 • Ovi •
The reverse-engineering write-up details the SuperBear RAT used in a campaign against civil society groups, focusing on the AutoIT stage and the injected Windows payload. The AutoIT script was compiled and packed, then used process hollowing to inject a decrypted PE into explorer.exe, where analysts found the C2-related strings. SuperBear created the mutex “BEARLDR-EURJ-RHRHR,” connected to hironchk[.]com over URI paths such as /id1, /id2, and /id3, and checked returned HTML for the “NdBrldr” watermark. Its commands supported process and system-information exfiltration via files under C:\Users\Public\Documents, shell-command download and execution, and Base64-encoded DLL retrieval followed by rundll32 execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 282e926eb90960a8a807dd0b9e8668e… | 2023-08-31 | 2023-09-15 |
| DOMAIN | hironchk.com | 2023-08-31 | 2023-09-15 |
| HASH | 5305b8969b33549b6bd4b68a3f9a2db… | 2023-08-31 | 2023-09-14 |
| HASH | 454cfe3be695d0a387d7877c11d3b22… | 2023-08-31 | 2023-09-14 |
| URL | https://syra.forumcommunity.net… | 2023-08-31 | 2023-09-14 |
| DOMAIN | autoit-script.ru | 2023-08-31 | 2023-09-14 |
| DOMAIN | syra.forumcommunity.net | 2023-08-31 | 2023-09-14 |