PULSE NAME
RTF Exploit Installs Italian RAT: uWarrior
WHITE AlienVault 2015-08-25 Modified: 2017-08-24
10
IOCs
LOW VOLUME
PaloAlto Unit 42 researchers have observed a new Remote Access Tool (RAT) constructed by an unknown actor of Italian origin. This RAT, referred to as uWarrior because of embedded PDB strings, has been previously described by an independent researcher who noted a potentially unknown exploit being used against Microsoft Office. Initial research into the exploit by Unit 42 indicates that this actor has opted to include multiple exploits. One is CVE-2012-1856, reinvigorated with a novel ROP chain to bypass ASLR and deliver the uWarrior payload. The other appears to be CVE-2015-1770. The malware itself is a fully featured RAT, which uses a compressed, (optionally) encrypted, raw TCP socket and binary message protocol for command and control communications. During the course of our research, it became evident that this actor had not built uWarrior from scratch, but rather opted to borrow components from several off-the-shelf tools. Linkages between older RATs are explored later in this blog.
Indicators of Compromise (10)
All FileHash-SHA256 hostname CVE FilePath
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 5dce01ec5e1bc1b4f5012e0b4bf16532206284fc8c64cfb8dcf907f45caf98fc 2017-08-24
FileHash-SHA256 57a5d0da72655df9c5ca9137df7210b86845eeabae488537c70e36587274937c 2017-08-24
FileHash-SHA256 a6dea088c9e2c9191e4c2fc4ece7b7b7bd3f034f444362d35c8765f6ec4bd279 2017-08-24
FileHash-SHA256 f4aa83297844eb8297711e32554e41f677cce290732171583199a57fb7a0674b 2017-08-24
hostname login.collegefan.org 2017-08-24
hostname login.loginto.me 2017-08-24
CVE CVE-2012-1856 2017-08-24
CVE CVE-2015-1770 2017-08-24
FilePath %AppData%\Local\Temp\bootloader.dec 2017-08-24
FilePath %AppData%\Roaming\warriors.dat 2017-08-24