In this twitch stream we conclude our three-part series on analyzing RitRat, a C++ RAT that is sold and generally used for eCrime activity but has also been linked to nation-stage backed targeted attacks.
The functionality of this RAT is fairly straight forward but its use of the C++ Standard Template Library makes reverse engineering a challenge. In this stream we finally setup the correct std::string type and our IDB magically begins to look like something readable... we then complete our analysis of the config encryption and build a static extractor in python.
Packed: 5e1ea26f5575e26857b209695de82207a04de0b0dc06f3645f776cc628440c46 [Malware Bazaar]
Unpacked 91e994fe2f5d97c9c7a8267ac900bd08d66c6e997397d01ccd15c0b301d98ea3 [Malshare]
Khải Phan Quang
2022-12-12 15:01:59 +0000 UTCOALABS
2022-11-02 23:53:17 +0000 UTCRobert Yates
2022-11-01 17:38:36 +0000 UTCOALABS
2022-11-01 17:03:40 +0000 UTCOALABS
2022-11-01 17:03:33 +0000 UTCRobert Yates
2022-11-01 01:12:02 +0000 UTC