# RootTeam Stealer and overlap issues on Bandit Stealer rule detection

**URL:** <https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744>\
**Category:** Rule Signatures\
**Created:** [July 11, 2023, 8:51am UTC](https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744 "2023-07-11T08:51:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![g0njxa](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/g0njxa/32/364_2.png) [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Post date:** [July 11, 2023, 8:51am UTC](https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744/1 "2023-07-11T08:51:49Z")

</div>

Hello Team,  
Recently a new stealer product was announced on the market and was discovered being distributed via Youtube compromised channels. Thanks to @AnFam17 for verifying such statement.

[Who said what on Twitter: “So this seems to be something new spotted on YT! #Root Team Stealer Uploading logs at temp linx server http://5.42.66.26/ (Same behaviour as for example Darth Project Stealer) Sandbox log: http://5.42.66.26/mk7nl8q3y3.zip 👇👇 https://t.co/xNrK4yRcsl” / Twitter](https://twitter.com/g0njxa/status/1675971998529323008)

Data from infected host is exfiltrated via **[http://5.42.66.26/upload](http://5.42.66.26/upload)** by default, an opensource Self-hosted file/media sharing website. (See [GitHub - xtrafrancyz/linx-server: Self-hosted file/code/media sharing website](https://github.com/xtrafrancyz/linx-server)). This behavior is similar to previous Darth Project Stealer, so maybe some rules can be reused to detect this threat.

[(2) Who said what on Twitter: “hxxps://github.com/zxcCitrus/tochnonefor/releases/download/gay/Download.zip Infostealer campaign spreading over Youtube C2 ⚙ #Darth Project Stealer 5.42.66.26 🇷🇺 (linx-server to upload temp files) Not a new stealer, but interesting to see it 👇👇 https://t.co/k0x9sUMNso” / Twitter](https://twitter.com/g0njxa/status/1661361906798542849)

One issue appeared with rule detection as this threat is actually being detected as Bandit Stealer, triggering rule **2045867 - ET MALWARE Bandit Stealer Reporting Attempt (malware.rules)**

You can find examples on AnyRun Public Submissions, tag: rootteam

Thanks to suyog41 for hashes

0e8d5189077b3bca3ce62d881a5adf54  
662317764cfae027c007ccbbe32046ef

I believe this kind of threats im sharing isn’t Bandit Stealer, they are RootTeam Stealer and this rule needs to be rewritten.  
Both Stealers uses /upload path to upload log files, but in fact Bandit Stealer always connect to a C2 panel [VirusTotal - File - 1b7e000c9cd800ca324537aa0532acd8dd497b67d07cdb522d1a4379a4a7b51e](https://www.virustotal.com/gui/file/1b7e000c9cd800ca324537aa0532acd8dd497b67d07cdb522d1a4379a4a7b51e/relations)  
[185.250.151.78 - urlscan.io](https://urlscan.io/result/edf4039d-b53c-44eb-96c0-9210f7fcf2fc/)  
and RootTeam Stealer uses the previous storage server mentioned.

Hope this issues can be verified by ET Labs Team and would love to see if @Jane\_0sint can help rewriting rules for Bandit Stealer and writing new rules for RootTeam Stealer

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [July 12, 2023, 9:14pm UTC](https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744/2 "2023-07-12T21:14:18Z")

</div>

hey @g0njxa

Thanks the additional intel! I’ve got that signature renamed in today’s release and found some additional traffic from the Any.Run detonation you shared in your tweet. Below is a summary of what changes/new signatures went out today. Let me know if anything looks off 👍

```auto
2046806 - Win32/RootTeam Stealer CnC Exfil M2. # Detects POST to /api/report
2046807 - Win32/RootTeam Stealer CnC Response # Detects CnC Response to PUT/POST /upload/
2046808 - DNS Query to File Sharing Domain (drop .xtrafrancyz .net) # DNS sig for demo links-server
2046809 - Upload to Links-Server File Sharing Server # Hunting sig for other links-server traffic

2045867 - Win32/RootTeam Stealer CnC Exfil M1 # Updated Name from Bandit Stealer

```

---

<div class="post-metadata">

**Author:** ![g0njxa](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/g0njxa/32/364_2.png) [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Post date:** [August 17, 2023, 5:10pm UTC](https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744/3 "2023-08-17T17:10:32Z")

</div>

a new variant has discovered of this stealer, currently there’s no rule detection. CnC exfil changed now log is being uploaded as base64 in a single request.

I dont know why 2046806 - Win32/RootTeam Stealer CnC Exfil M2. # Detects POST to /api/report is not being pushed

OLD:  
[Analysis Launcher.exe (MD5: 525ECA0E85C3325ECA5B5B3CFEACD241) Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/da0c4adf-53e7-484f-bad6-e643fd513a8b/)

NEW:  
[Analysis LaLauncher.exe (MD5: 43A3997C24E25E4B25F66AFF503ACE89) Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/616ca90b-9f70-4d8c-ab9b-68ae70ab65d2)

the other PE file being dropped by this stealer is a clipper that now is being loaded by the new variants too

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [August 17, 2023, 8:09pm UTC](https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744/4 "2023-08-17T20:09:28Z")

</div>

Hi!  
it looks like there have been some changes in the headers and the http request. I propose new rules for detection.

> **[Analysis LaLauncher.exe (MD5: 43A3997C24E25E4B25F66AFF503ACE89) Malicious...](https://app.any.run/tasks/683afc31-29e0-4803-964b-f11036ff0f20/)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

> <https://twitter.com/Jane_0sint/status/1692264873026088986?s=20>

```auto
alert http any any -> any any (msg: "ET MALWARE [ANY.RUN] Win32/RootTeam Stealer User-Agent";flow: established, to_server; http.method; content: "POST"; http.user_agent; content: "Mozilla/5.0 (Windows NT 123.9|3b| WOW64) AppleWebKit / 537.36 (KHTML, like Gecko) Chrome / 83.0.4.121 Safari/537.36"; http.header_names; content:!"Referer|0d 0a|"; reference: md5,6bb365fb7263551c97317f071aa73276; reference: url,app.any.run/tasks/616ca90b-9f70-4d8c-ab9b-68ae70ab65d2; metadata: attack_target Client_Endpoint, deployment Perimeter, former_category MALWARE, signature_severity Major, malware_family RootTeam, reated_at 2023_08_17; classtype: trojan-activity; sid: 8000686; rev: 1;)

alert http any any -> any any (msg: "ET MALWARE [ANY.RUN] Win32/RootTeam Stealer CnC Exfil M3";flow: established, to_server; http.method; content: "POST"; http.header; content: "Content-Type: application/json"; http.header_names; content:!"Referer|0d 0a|"; http.request_body;content: "{|22|log|22|:|22|UEs";content: "|22|,|22|passwords|22|:|22|"; distance: 0; content: "|22|,|22|cookies|22|:|22|"; distance: 0; content: "|22|,|22|wallets|22|:|22|"; distance: 0; content: "|22|,|22|name|22|:|22|"; distance: 0; content: "|22|,|22|inC|22|:|22|"; distance: 0; content: "|22|,|22|nickname|22|:|22|"; distance: 0; reference: md5,6bb365fb7263551c97317f071aa73276; reference: url,app.any.run/tasks/616ca90b-9f70-4d8c-ab9b-68ae70ab65d2; metadata: attack_target Client_Endpoint, deployment Perimeter, former_category MALWARE, signature_severity Major, malware_family RootTeam, created_at 2023_08_17; classtype: trojan-activity; sid: 8000687; rev: 1;)

```

Best regards, Jane.

---

<div class="post-metadata">

**Author:** ![jtaylor](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jtaylor/32/12_2.png) [@jtaylor](https://community.emergingthreats.net/u/jtaylor)\
**Post date:** [August 17, 2023, 9:05pm UTC](https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744/5 "2023-08-17T21:05:55Z")

</div>

Thank you both for the report, we will have the rules in for tomorrows release!

JT

---

<div class="post-metadata">

**Author:** ![jtaylor](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jtaylor/32/12_2.png) [@jtaylor](https://community.emergingthreats.net/u/jtaylor)\
**Post date:** [August 18, 2023, 9:30pm UTC](https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744/6 "2023-08-18T21:30:37Z")

</div>

2047671 - ET MALWARE [ANY.RUN] Win32/RootTeam Stealer Related User-Agent  
2047672 - ET MALWARE [ANY.RUN] Win32/RootTeam Stealer CnC Exfil M3

Went out today, thanks again!

JT

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [August 29, 2023, 7:00am UTC](https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744/7 "2023-08-29T07:00:22Z")

</div>

> [@jtaylor](#):
>
> 2047672 - ET MALWARE [ANY.RUN] Win32/RootTeam Stealer CnC Exfil M3

Hi, let’s modify the rules for exfiltration:

```auto
alert http any any -> any any (msg: "ET MALWARE [ANY.RUN] Win32/RootTeam Stealer CnC Exfil M3";flow: established, to_server; http.method;content: "POST"; http.header;content: "Content-Type: application/json"; http.header_names;content:!"Referer|0d 0a|"; http.request_body;content: "|22|log|22|:|22|UEs";content: "|22|,|22|passwords|22|:|22|"; content: "|22|cookies|22|:|22|"; content: "|22|wallets|22|:|22|"; content: "|22|name|22|:|22|"; content: "|22|nickname|22|:|22|"; reference: md5,6bb365fb7263551c97317f071aa73276;reference: url,app.any.run/tasks/616ca90b-9f70-4d8c-ab9b-68ae70ab65d2;metadata: attack_target Client_Endpoint, deployment Perimeter, former_category MALWARE, signature_severity Major, malware_family RootTeam, created_at 2023_08_17; classtype: trojan-activity;sid: 8000687; rev: 2;)

```

> **[Analysis Launcher.exe (MD5: 07D97311EFA4FD06743A276F4D22960F) Malicious...](https://app.any.run/tasks/fb27dd2a-c508-41be-80d6-8368da4d15d3/)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

Best regards, Jane

---

<div class="post-metadata">

**Author:** ![jtaylor](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jtaylor/32/12_2.png) [@jtaylor](https://community.emergingthreats.net/u/jtaylor)\
**Post date:** [August 29, 2023, 5:41pm UTC](https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744/8 "2023-08-29T17:41:56Z")

</div>

Thanks, we will get this in for todays release!

JT
