# RadX RAT

**URL:** <https://community.emergingthreats.net/t/radx-rat/1316>\
**Category:** Rule Signatures\
**Created:** [January 24, 2024, 8:42am UTC](https://community.emergingthreats.net/t/radx-rat/1316 "2024-01-24T08:42:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [January 24, 2024, 8:42am UTC](https://community.emergingthreats.net/t/radx-rat/1316/1 "2024-01-24T08:42:56Z")

</div>

Hi guys! Here is an article in Russian about the new malware, we already have it in the sandbox, so I propose rules for Check-In and for KeepAlive.  
[https://www.facct.ru/blog/radx-rat/](https://www.facct.ru/blog/radx-rat/)

```auto
alert http any any -> any any (msg: "ET MALWARE [ANY.RUN] RadX RAT HTTP POST Check-In";flow: established, to_server; http.method; content: "POST"; http.uri; content: "/add_user"; endswith; http.header; content: "Content-Type: application/json|3b| charset=utf-8"; http.header_names; content:!"User-Agent|0d 0a|";http.request_body;content: "|22|video_card|22|"; depth: 1000; content: "|22|windows_version|22|"; depth: 1000; content: "|22|processor|22|"; depth: 1000; content: "|22|ram|22|"; depth: 1000; reference: md5,f0bc8d8a0ecd2ff441c9a24f907bd9db; reference: url,app.any.run/tasks/4fdde064-e353-4325-81ef-d85b22ee0f90; metadata: attack_target Client_Endpoint, deployment Perimeter, former_category MALWARE, signature_severity Major, malware_family RadX, created_at 2024_01_24; classtype: trojan-activity; sid: 1; rev: 1;)

```

The body of the requests contains JSON and I am not sure about the order of the keys, so I left them free in the range of up to 1000 characters.

> **[Analysis fcafcfd32332f92ac7735324411d671a7e49da7159c24c15e34603e7638429aa...](https://app.any.run/tasks/4fdde064-e353-4325-81ef-d85b22ee0f90/)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

And it also seems to me that it incorrectly calculates the identifier because it becomes negative

**POST /check/-7635670199524603949 HTTP/1.1  
Host: 193.106.95.60:1337  
Content-Length: 0**

```auto
alert http any any -> any any (msg: "ET MALWARE [ANY.RUN] RadX RAT HTTP POST Keep-Alive";flow: established, to_server; http.method; content: "POST"; http.uri; content: "/check/-"; http.header; content: "Content-Length: 0|0d0a|"; distance: 0; http.header_names; content: "|0d 0a|Host|0d 0a|Content-Length|0d 0a 0d 0a|"; startswith; reference: md5, f0bc8d8a0ecd2ff441c9a24f907bd9db; reference: url, https://app.any.run/tasks/4fdde064-e353-4325-81ef-d85b22ee0f90; metadata: attack_target Client_Endpoint, deployment Perimeter, former_category MALWARE, signature_severity Major, malware_family RadX, created_at 2024_01_24; classtype: trojan-activity; sid: 2; rev: 1;)

```

I did not sign the rest of the activity; it seemed that this would be enough.  
⋆┈┈｡ﾟ❃ུ۪ ❀ུ۪ ❁ུ۪ ❃ུ۪ ❀ུ۪ ﾟ｡┈┈⋆  
Jane

---

<div class="post-metadata">

**Author:** ![jtaylor](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jtaylor/32/12_2.png) [@jtaylor](https://community.emergingthreats.net/u/jtaylor)\
**Post date:** [January 24, 2024, 7:30pm UTC](https://community.emergingthreats.net/t/radx-rat/1316/2 "2024-01-24T19:30:47Z")

</div>

Thanks! We will get these in for todays release.

JT

---

<div class="post-metadata">

**Author:** ![jtaylor](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jtaylor/32/12_2.png) [@jtaylor](https://community.emergingthreats.net/u/jtaylor)\
**Post date:** [January 24, 2024, 11:02pm UTC](https://community.emergingthreats.net/t/radx-rat/1316/3 "2024-01-24T23:02:54Z")

</div>

Just made a couple minor tweaks to the submitted rules and these went out today,

2050419 - ET MALWARE [ANY.RUN] RadX RAT Check-In (POST)  
2050420 - ET MALWARE [ANY.RUN] RadX RAT Keep-Alive Activity (POST)

Thanks Jane, very cool stuff!

JT
