chartingshow / crypto-firewall

🎁 Blocks browser-based crypto mining, cryptojacking, banking and crypto malware and phishing websites, apps and hackers command-and-control (C2) servers.
GNU General Public License v3.0
7 stars 0 forks source link

Block `NineRAT` Malware written in DLang by Lazarus group #408

Closed summercms closed 6 months ago

summercms commented 6 months ago

Enhancement idea

Description

Operation Blacksmith involved the exploitation of CVE-2021-44228, also known as Log4Shell, and the use of a previously unknown DLang-based RAT utilizing Telegram as its C2 channel. We’re naming this malware family “NineRAT.” NineRAT was initially built around May 2022 and was first used in this campaign as early as March 2023, almost a year later, against a South American agricultural organization. We then saw NineRAT being used again around September 2023 against a European manufacturing entity.

Links

https://blog.talosintelligence.com/lazarus_new_rats_dlang_and_telegram/

IOC

I2P websites

n/a

IPFS websites

n/a

Tor2web websites

n/a

TOR websites

n/a

URL's

n/a

Folders

n/a

Sub-Domains

n/a

Domains

micrsofts.com
micrsofts.tech

IP's

155.94.208.209
162.19.71.175
185.29.8.53
201.77.179.66
27.102.113.93

Emails

n/a

Wallet addresses

n/a

Mining pool addresses

n/a