Live Stream VOD: BitRat Analysis (C++) - Part 3 (Patreon)
Content
In this twitch stream we conclude our three-part series on analyzing RitRat, a C++ RAT that is sold and generally used for eCrime activity but has also been linked to nation-stage backed targeted attacks.
The functionality of this RAT is fairly straight forward but its use of the C++ Standard Template Library makes reverse engineering a challenge. In this stream we finally setup the correct std::string type and our IDB magically begins to look like something readable... we then complete our analysis of the config encryption and build a static extractor in python.
Sample
Packed: 5e1ea26f5575e26857b209695de82207a04de0b0dc06f3645f776cc628440c46 [Malware Bazaar]
Unpacked 91e994fe2f5d97c9c7a8267ac900bd08d66c6e997397d01ccd15c0b301d98ea3 [Malshare]