# DarkCrystal RAT

**URL:** <https://community.emergingthreats.net/t/darkcrystal-rat/952>\
**Category:** Rule Signatures\
**Created:** [September 15, 2023, 7:23pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952 "2023-09-15T19:23:08Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [September 15, 2023, 7:23pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/1 "2023-09-15T19:23:08Z")

</div>

Hello again!  
Our good friend James found DCrat malware traffic with a new encryption layer

> <https://twitter.com/James_inthe_box/status/1702725346762825909?s=20>

In turn, I quickly compared the first 344 byte check-ins and received static bytes.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/2d6f8cc33e91cdce64bd2e657e093d8fd0b52121.jpeg)  
Probably the rule will be further clarified, I’m working on deciphering it.  
But for now I dare to propose the following solution

```auto
alert http any any -> any any (msg: "ET MALWARE [ANY.RUN] DarkCrystal Rat Check-in";flow: established, to_server; http.method; content: "POST"; http.header; content: "Content-Length: 344|0d0a|"; http.request_body;content: "|7106 785c 7908 5669 0804|"; endswith; reference: md5,8dd1baebdcaee56ce4e4382e7071bd3d; reference: url,app.any.run/tasks/730814fe-b061-4b67-8ff1-4455998e99f6; metadata: attack_target Client_Endpoint, deployment Perimeter, former_category MALWARE, signature_severity Major, malware_family DarkCrystal, created_at 2023_09_15; classtype: command-and-control; sid: 1; rev: 1;)

```

Keep in touch, Jane

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [September 15, 2023, 9:53pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/2 "2023-09-15T21:53:23Z")

</div>

thanks @Jane0sint !

`2048095 - ET MALWARE [ANY.RUN] DarkCrystal Rat Check-in (POST)`

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [September 20, 2023, 3:59pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/3 "2023-09-20T15:59:52Z")

</div>

As expected, the new sample doesn’t trigger as a rule, I’m working on improving it.

> **[Analysis ccd934c7dd80e3c5281f6912e8e5923e.exe (MD5:...](https://app.any.run/tasks/7aebaa50-c790-438c-93a5-4602f3dcefa7/)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [September 20, 2023, 4:37pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/4 "2023-09-20T16:37:39Z")

</div>

I made changes to the length of the http request body, renew the 5 bytes fragments in the body (still waiting for the reverse), set the order of the headers and the php extension

```auto
alert http any any -> any any 
(msg: "ET MALWARE [ANY.RUN] DarkCrystal Rat Check-in (POST)";
flow: established, to_server; 
http.method; content: "POST"; 
http.uri; content: ".php"; endswith; 

http.content_len; 
byte_test:0,>,320,0,string,dec; 
byte_test:0,<,370,0,string,dec; 

http.request_body; 
content: "|05 06 02 01 02|";offset:8;depth:5;fast_pattern; 

http.header; 
content:"Expect|3a 20|100|2d|continue"; 

http.header_names; content: "|0d 0a|Content-Type|0d 0a|User-Agent|0d 0a|Host|0d 0a|Content-Length|0d 0a|Expect|0d 0a|Connection|0d 0a 0d 0a|"; bsize: 72; 
content:!"Referer|0d 0a|"; 
 
reference: md5,ec01cff4cf0004f1b6c934d7263f5023; 
reference: url,app.any.run/tasks/7aebaa50-c790-438c-93a5-4602f3dcefa7; 

classtype:trojan-activity; sid:2048095; rev:2; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2023_09_15, deployment Perimeter, former_category MALWARE, malware_family DCRat, confidence High, signature_severity Critical, updated_at 2023_09_15, reviewed_at 2023_09_15;)

```

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [September 20, 2023, 4:51pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/5 "2023-09-20T16:51:55Z")

</div>

I also discovered the exfiltration process via HTTP post request

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/7f1a9474e956c52e5d7832e396befd98299a9a05.jpeg)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/8afab57f9f550bc7a357197492ad5ba0fc2983af.png)

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [September 20, 2023, 5:31pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/6 "2023-09-20T17:31:32Z")

</div>

Taking a look at updating the previous sig and the new traffic now! 😺

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [September 20, 2023, 5:42pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/7 "2023-09-20T17:42:24Z")

</div>

Another launch on Windows 8

> **[Analysis ccd934c7dd80e3c5281f6912e8e5923e.exe (MD5:...](https://app.any.run/tasks/dad1cdd5-f8de-4636-9b15-2c6433f20958/)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [September 20, 2023, 6:28pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/8 "2023-09-20T18:28:21Z")

</div>

The rule for exfiltration could be like this:

```auto
alert http any any -> any any (msg: "ET MALWARE [ANY.RUN] DarkCrystal Rat Exfiltration";
flow: established, to_server; 
http.method;content: "POST";
http.uri;content: ".php"; endswith;
http.request_body;
content: "------";  
content: "|0d 0a|Content-Disposition: form-data|3b| name=|22|0|22 0d 0a|Content-Type: text/plain|0d0a 0d0a|"; distance: 34; within: 72; 
content: "Content-Disposition: form-data|3b| name=|22|"; distance: 0;
pcre: "/^([a-f0-9]{40})\x22\x3b\x20filename=\x22\1\x22/R";
content: "|0d 0a|Content-Type: application/octet-stream|0d 0a 0d 0a|UEsD"; within: 48; http.header;
content:"Expect|3a 20|100|2d|continue";
http.header_names;
content: "|0d 0a|Content-Type|0d 0a|User-Agent|0d 0a|Host|0d 0a|Content-Length|0d 0a|Expect|0d 0a 0d 0a|";
content:!"Referer|0d 0a|";
reference: md5,ec01cff4cf0004f1b6c934d7263f5023; 
reference: url,app.any.run/tasks/79b78536-75bf-43b4-99d6-3438ba41e40c; 
classtype: trojan-activity; 
sid:1; rev:1; 
metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2023_09_20, deployment Perimeter, former_category MALWARE, malware_family DCRat, confidence High, signature_severity Critical, updated_at 2023_09_20;)

```

Best regards, Jane ⋆⭒˚｡⋆

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [September 20, 2023, 8:42pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/9 "2023-09-20T20:42:41Z")

</div>

@Jane0sint

Nice work! One thing I was going to share is that with http.header\_names you don’t need to include the negation `content:!"Referer|0d 0a|";` because `bsize:72;` is already restricting any additional data in that buffer. I’m not sure if there is any performance impact so its fine to leave it in there but it’s not required. After updating 2048095 it alerts on the old pcap as well as the new captures. 🎉

**Sid for the new signature:**

```auto
2048130 - ET MALWARE [ANY.RUN] DarkCrystal Rat Exfiltration (POST)

```

Here are a few things I changed:

Instead of using `Content-Disposition: form-data; name="0"` I used pcre so that the rule will alert if any single digit name is used.

i.e. I replaced this

```auto
content: "|0d 0a|Content-Disposition: form-data|3b| name=|22|0|22 0d 0a|Content-Type: text/plain|0d0a 0d0a|";

```

with this:

```auto
content:"Content|2d|Disposition|3a 20|form|2d|data|3b 20|name|3d 22|"; 
pcre:"/^(?:[0-9]{1})/R"; 
content:"|22 0d 0a|Content|2d|Type|3a 20|text|2f|plain"; within:28;

```

I noticed in the pcap that the name/filename values were identical 40 character strings so I updated your pcre to use a **named capture group**. A named capture group essentially lets you store a regex match into a variable so that you can use it again without duplicating your pcre pattern.

 ![Screenshot 2023-09-20 at 2.02.26 PM](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/2415846c64a94ab103a3ca82e8f025a8b3f442d6.png)

This is the pcre that I came up with which uses the variable `filename`:

```auto
pcre:"/^(?P<filename>[a-z0-9]{40})\x22\x3b\x20filename\x3d\x22(?P=filename)\x22/R";

```

This part will match a 40 character string and store it in the variable `filename`

```auto
pcre:"/^(?P<filename>[a-z0-9]{40}) - matches 68c36a2defa8620c47b3f5dca991c77583292318

```

And this is how you can access that same value again

```auto
filename\x3d\x22(?P=filename)\x22 - which equates to filename="68c36a2defa8620c47b3f5dca991c77583292318"

```

Ultimately this lets us match exactly on

```auto
name="68c36a2defa8620c47b3f5dca991c77583292318"; filename="68c36a2defa8620c47b3f5dca991c77583292318"

```

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [September 21, 2023, 5:51am UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/10 "2023-09-21T05:51:56Z")

</div>

Hi!  
Thanks for the edit! It’s great that you write in such detail.

```auto
content: "|0d 0a|Content-Type|0d 0a|User-Agent|0d 0a|Host|0d 0a|Content-Length|0d 0a|Expect|0d 0a 0d 0a|";

```

The http header buffer doesn’t really allow for additional parameters, there’s just no size for anything else! I need to be more careful and not rush too much.

```auto
pcre: "/^([a-f0-9]{40})\x22\x3b\x20filename=\x22\1\x22/R";

```

The group in my regular expression is not named, it is called - \1 - since it is the first one.  
But I agree that with a name it looks much clearer. Speed up the writing process a little by indicating the number ¯\_(ツ)_/¯ it’s cool that you expanded this thought into a clear expression.

## [Description](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Regular_expressions/Named_capturing_group#description)

> Named capturing groups can be used just like capturing groups — they also have their match index in the result array, and they can be referenced through `\1`, `\2`, etc. The only difference is that they can be _additionally_ referenced by their name. The information of the capturing group’s match can be accessed through:

> **[Named capturing group: (?...) - JavaScript | MDN](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Regular_expressions/Named_capturing_group)**
>
> A named capturing group is a particular kind of capturing group that allows to give a name to the group. The group's matching result can later be identified by this name instead of by its index in the pattern.

I’d love to hear your thoughts, Jane! ✿ڿڰۣ—

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [September 21, 2023, 6:50pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/11 "2023-09-21T18:50:50Z")

</div>

ah I overlooked the `\1` in your pcre! 🤦‍♂️ I actually didn’t know you could perform a back reference like that so thank for sharing that tip!

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [September 21, 2023, 8:09pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/12 "2023-09-21T20:09:23Z")

</div>

It’s so interesting to know that the idea to compare these parameters came to you too. You didn’t know I did it. Being in the same vibe is a thrill.⊹╰(⌣ʟ⌣)╯⊹

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [December 29, 2023, 6:26am UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/13 "2023-12-29T06:26:20Z")

</div>

Hi again! Look what we came up with on any.run, display reference links and descriptions in the threat window.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/3abde49071fd919e63929714e93df8c62e0f5a13.png)  
I would like to participate in the writing of both! Now the question is how to send you a description? Is there a form somewhere for submitting descriptions and links to sources?  
Best wishes for the New Year! ✩₊˚.⋆☾⋆⁺₊✧  
Jane.

---

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [January 2, 2024, 9:24pm UTC](https://community.emergingthreats.net/t/darkcrystal-rat/952/14 "2024-01-02T21:24:38Z")

</div>

Awesome! You can leave a post here of course or drop a comprehensive mail at support(at)emergingthreats(dot)net and we’ll incorporate that into our internal descriptions!
