ROKRAT is Back

2018-09-21 v3lo

http://v3lo.tistory.com/21

Thumbnail for ROKRAT is Back

The source analyzes a Korean HWP malware sample described as similar to earlier ROKRAT activity, with VirusTotal showing the Hangul document as undetected at the time. The infection chain converts shellcode into PE files under the Temp directory, creates WinUpdate148399843.pif, and uses Themida packing followed by thread injection. The injected payload includes anti-debugging and anti-sandbox behavior, including destructive MBR overwrite behavior in a virtual machine environment, and collects host details such as computer name, user name, SMBIOS information, process lists, and screenshots. The malware contains cloud-service API strings for Box, Dropbox, pCloud, and Yandex, suggesting cloud storage was used for command, file transfer, or data handling, although the C2 was dead during analysis. Similar SMBIOS collection, anti-sandbox DLL targeting, packet headers, and function overlap are cited as evidence connecting the sample to ROKRAT-like tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://content.dropboxapi.com/… 2018-09-21 2025-09-03
URL https://api.dropboxapi.com/2/fi… 2018-09-21 2025-08-29
URL https://api.pcloud.com/deletefi… 2018-09-21 2025-08-29
DOMAIN cloud-api.yandex.net 2018-02-27 2025-08-29
HASH b3de3f9309b2f320738772353eb724a… 2018-01-16 2025-04-01
HASH 51e35a7a4e2c49670ecfba7b55045cf… 2018-09-21 2018-09-21
HASH 41a3e61adf853edaddc999e547a246c… 2018-09-21 2018-09-21
HASH 52976314913289a61282ee1f172a30c… 2018-09-21 2018-09-21
HASH bedc4b9f39dcc0907f8645db1acce59e 2018-09-21 2018-09-21
HASH 3f92afe96b4cfd41f512166c691197b5 2018-09-21 2018-09-21
HASH 98498b97b7cdce9dd6b1a83057e47bd… 2018-09-21 2018-09-21
HASH 6ec89edfffdb221a1edbc9852a9a567a 2018-09-21 2018-09-21
HASH eeae06fc31982f992993ef0ff12e2d9… 2018-09-21 2018-09-21
HASH 7a751874ea5f9c95e8f0550a0b93902d 2018-09-21 2018-09-21
HASH e68dca8bbfaf785ff4a9de43d91bbef… 2018-09-21 2018-09-21
HASH f885c37b3368faf2ae11d70e15aa75a… 2018-09-21 2018-09-21
URL https://my.pcloud.com/oauth2/au… 2018-09-21 2018-09-21
URL https://api.pcloud.com/uploadfi… 2018-09-21 2018-09-21
URL https://cloud-api.yandex.net/v1… 2018-09-21 2018-09-21
URL https://content.dropboxapi.com/… 2018-09-21 2018-09-21
URL https://cloud-api.yandex.net/v1… 2018-09-21 2018-09-21
URL https://cloud-api.yandex.net/v1… 2018-09-21 2018-09-21
URL https://api.pcloud.com/getfilel… 2018-09-21 2018-09-21
URL https://api.pcloud.com/oauth2_t… 2018-09-21 2018-09-21

Related Reports

« Back