--- name: rat-analysis description: > Analyze Remote Access Trojans (RATs) including AsyncRAT, NjRAT, QuasarRAT, Remcos, DarkComet, and Warzone RAT. Covers family identification, plugin architecture analysis, C2 protocol reverse engineering, capability enumeration, configuration extraction (C2 host/port, mutex, encryption keys), persistence mechanisms, and .NET RAT decompilation. Use when analyzing samples exhibiting remote control capabilities. --- # RAT Analysis Analyze Remote Access Trojans to identify the family, extract configurations, understand capabilities, and map the C2 infrastructure. ## Prerequisites - **Python 3.10+**: `pefile`, `dnfile`, `pycryptodome`, `yara-python` - **Tools**: dnSpy, ILSpy, de4dot, Ghidra/IDA Pro, x64dbg, Wireshark - **.NET tools**: Most commodity RATs are .NET-based; dnSpy is essential - **Environment**: Isolated VM with network capture enabled ## Step-by-Step Instructions ### Step 1: Identify the RAT Family Determine which RAT family the sample belongs to. **Run family identification:** ```bash python3 scripts/rat_analyzer.py --sample suspicious.exe --mode identify --output rat_id.json ``` **Family identification markers:** | Family | Key Indicators | |--------|---------------| | AsyncRAT | .NET binary, `AsyncClient` namespace, AES-encrypted config, Pastebin C2 delivery | | NjRAT | .NET binary, `njq8` mutex pattern, base64 config in resources, `\|'\\|\|'\\|` delimiter | | QuasarRAT | .NET binary, `Client.Config` class, AES-256 encrypted settings, certificate pinning | | Remcos | C++ binary, `SETTINGS` resource section, RC4-encrypted config, IPLK mutex | | DarkComet | Delphi binary, `DC_MUTEX-` prefix, `#KCMDDC` commands, `.ini` config | | Warzone (AveMaria) | C++ binary, `AVE_MARIA` mutex, RDP-based lateral movement | **Quick .NET check:** ```bash # Check if sample is .NET file suspicious.exe | grep -i "mono\|\.net\|msil\|pe32.*clr" # Check for .NET metadata python3 -c " import pefile, sys pe = pefile.PE(sys.argv[1]) clr = pe.OPTIONAL_HEADER.DATA_DIRECTORY[14] # COM_DESCRIPTOR print(f'CLR header: size={clr.Size}, rva=0x{clr.VirtualAddress:x}') print('.NET binary' if clr.Size > 0 else 'Native binary') " suspicious.exe ``` ### Step 2: Decompile .NET RATs Most commodity RATs are written in .NET and can be fully decompiled. **Deobfuscation (if protected):** ```bash # Run de4dot to remove common .NET obfuscation de4dot suspicious.exe -o deobfuscated.exe # Common protectors used by RATs: # ConfuserEx, SmartAssembly, .NET Reactor, Crypto Obfuscator de4dot suspicious.exe --detect-only # Identify the protector ``` **Decompilation with dnSpy/ILSpy:** ```bash # Open in dnSpy for interactive analysis dnSpy deobfuscated.exe # Or use ILSpy command-line ilspycmd deobfuscated.exe -o ./decompiled/ ``` **Key classes to examine:** - `Settings` / `Config` — C2 configuration - `Client` / `Connection` — Network communication - `Plugin` / `Module` — Capability plugins - `Install` / `Persistence` — Installation logic - `Crypto` / `Encryption` — Communication encryption ### Step 3: Extract Configuration Pull out the embedded C2 configuration. **Automated extraction:** ```bash python3 scripts/rat_analyzer.py --sample suspicious.exe --mode config --output rat_config.json ``` **AsyncRAT config extraction:** ```python # AsyncRAT stores config as encrypted strings in the Settings class # Key is typically derived from a hardcoded string using PBKDF2 import base64 from Crypto.Cipher import AES from Crypto.Protocol.KDF import PBKDF2 def decrypt_asyncrat_config(encrypted_b64: str, key_string: str, salt: bytes) -> str: key = PBKDF2(key_string.encode(), salt, dkLen=32, count=50000) data = base64.b64decode(encrypted_b64) iv = data[:16] cipher = AES.new(key, AES.MODE_CBC, iv) decrypted = cipher.decrypt(data[16:]) # Remove PKCS7 padding pad_len = decrypted[-1] return decrypted[:-pad_len].decode() ``` **NjRAT config extraction:** ```python # NjRAT typically stores config as base64-encoded strings # separated by a delimiter (|'|) in the binary import base64, re def extract_njrat_config(data: bytes) -> dict: # Find the delimiter pattern pattern = rb"[A-Za-z0-9+/=]{4,}\|'\\\|" matches = re.findall(pattern, data) config_parts = [] for m in matches: try: decoded = base64.b64decode(m.split(b"|")[0]) config_parts.append(decoded.decode()) except Exception: pass return { "host": config_parts[0] if len(config_parts) > 0 else "", "port": config_parts[1] if len(config_parts) > 1 else "", "install_name": config_parts[2] if len(config_parts) > 2 else "", } ``` **Remcos config extraction:** ```python # Remcos stores RC4-encrypted config in the SETTINGS resource import pefile def extract_remcos_config(filepath: str) -> dict: pe = pefile.PE(filepath) for entry in pe.DIRECTORY_ENTRY_RESOURCE.entries: if hasattr(entry, 'directory'): for res in entry.directory.entries: if res.name and str(res.name) == "SETTINGS": data = pe.get_data( res.directory.entries[0].data.struct.OffsetToData, res.directory.entries[0].data.struct.Size ) key_len = data[0] key = data[1:1+key_len] encrypted = data[1+key_len:] # RC4 decrypt from Crypto.Cipher import ARC4 decrypted = ARC4.new(key).decrypt(encrypted) # Parse pipe-delimited config fields = decrypted.split(b"\x1e") return { "c2_host": fields[0].decode() if fields else "", "c2_port": fields[1].decode() if len(fields) > 1 else "", "password": fields[2].decode() if len(fields) > 2 else "", "mutex": fields[3].decode() if len(fields) > 3 else "", } return {} ``` ### Step 4: Enumerate Capabilities Document what the RAT can do on infected systems. **Capability scan:** ```bash python3 scripts/rat_analyzer.py --sample suspicious.exe --mode capabilities --output capabilities.json ``` **Common RAT capabilities:** | Category | Capability | Indicators | |----------|-----------|------------| | Surveillance | Keylogger | GetAsyncKeyState, SetWindowsHookEx | | Surveillance | Screen capture | BitBlt, GetDesktopWindow, CopyFromScreen | | Surveillance | Webcam | avicap32.dll, capCreateCaptureWindow | | Surveillance | Audio recording | mciSendString, waveInOpen | | File ops | File manager | GetFiles, Upload, Download commands | | File ops | File search | SearchFiles, FindFirstFile patterns | | Execution | Remote shell | cmd.exe /c, Process.Start, ShellExecute | | Execution | Script execution | PowerShell, cscript, wscript | | Credentials | Browser passwords | SQLite queries on Login Data, logins.json | | Credentials | Clipboard | GetClipboardData, SetClipboardViewer | | Network | Reverse proxy | SOCKS proxy, port forwarding | | Network | DDoS | UDP/TCP/HTTP flood functions | | System | Process manager | Process.GetProcesses, TerminateProcess | | System | Registry editor | RegistryKey.OpenSubKey, RegSetValue | ### Step 5: Reverse Engineer the C2 Protocol Understand the command-and-control communication protocol. **Capture C2 traffic:** ```bash # Run sample with network monitoring python3 scripts/rat_analyzer.py --sample suspicious.exe --mode c2-protocol --output protocol.json ``` **Common C2 protocol patterns:** | Family | Protocol | Encoding | Delimiter | |--------|----------|----------|-----------| | AsyncRAT | TCP | AES + gzip + base64 | Packet length header | | NjRAT | TCP | Base64 | `\|'\\|\|'\\|` | | QuasarRAT | TCP | AES-256 + protobuf-like | Length-prefixed | | Remcos | TCP | RC4 | Custom binary header | | DarkComet | TCP | Custom encoding | `\|` pipe delimiter | **Protocol analysis approach:** 1. Capture initial beacon with Wireshark 2. Identify the packet structure (length prefix, delimiters, encoding) 3. Extract encryption keys from the config 4. Decrypt captured traffic 5. Map command IDs to functionality 6. Document request/response format ### Step 6: Analyze Persistence Mechanisms Determine how the RAT maintains access across reboots. **Check persistence:** ```bash python3 scripts/rat_analyzer.py --sample suspicious.exe --mode persistence --output persistence.json ``` **Common RAT persistence methods:** | Method | Registry/Path | Families | |--------|--------------|----------| | Run key | `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` | Most RATs | | Startup folder | `%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup` | NjRAT, AsyncRAT | | Scheduled task | `schtasks /create /sc onlogon` | QuasarRAT, Remcos | | WMI subscription | `__EventFilter` + `CommandLineEventConsumer` | Advanced variants | **Strings to search for:** ```bash strings suspicious.exe | grep -iE "(CurrentVersion\\\\Run|Startup|schtasks|TaskScheduler)" ``` ### Step 7: Analyze Plugin Architecture Many RATs support modular plugins loaded at runtime. **Plugin analysis:** ```bash python3 scripts/rat_analyzer.py --sample suspicious.exe --mode plugins --output plugins.json ``` **Common plugin types:** - **Keylogger**: Separate module for keystroke capture - **Reverse proxy**: SOCKS4/5 proxy module - **HVNC**: Hidden Virtual Network Computing for stealth RDP - **File recovery**: Deleted file recovery capabilities - **Crypto miner**: XMRig integration in some variants - **Spreader**: USB/network propagation module ### Step 8: Build Detections and Extract IOCs Create detection rules based on the analysis. **Generate YARA rule:** ```bash python3 scripts/rat_analyzer.py --sample suspicious.exe --mode iocs --output rat_iocs.json ``` **Key IOCs to extract:** - C2 server addresses and ports - Mutex names (often unique per builder/campaign) - Installation paths and filenames - Registry key paths - Certificate thumbprints (for QuasarRAT) - Encryption keys and salts - Campaign/group identifiers ## Output Format ```json { "family": "AsyncRAT", "version": "0.5.8", "confidence": "high", "dotnet": true, "obfuscation": "ConfuserEx (deobfuscated with de4dot)", "config": { "c2_host": "evil.example.com", "c2_port": 6606, "mutex": "AsyncMutex_6SI8OkPnk", "install_path": "%AppData%\\svchost.exe", "encryption_key": "password123", "group": "Default", "anti_vm": true, "persistence": true }, "capabilities": [ "keylogger", "screen_capture", "file_manager", "remote_shell", "process_manager", "webcam", "browser_credential_theft", "clipboard_monitoring" ], "persistence": { "method": "registry_run_key", "key": "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\svchost", "scheduled_task": false }, "c2_protocol": { "transport": "TCP", "encryption": "AES-256-CBC", "encoding": "gzip + base64", "keepalive_interval": 5 }, "iocs": { "c2_domains": ["evil.example.com"], "c2_ips": ["198.51.100.30"], "mutex": "AsyncMutex_6SI8OkPnk", "file_paths": ["%AppData%\\svchost.exe"], "registry_keys": ["HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\svchost"] }, "mitre_attack": ["T1219", "T1056.001", "T1113", "T1547.001", "T1573.001"] } ``` ## Tips - Most commodity RATs are .NET — start with dnSpy for fastest results - Run de4dot before decompilation to strip obfuscation (ConfuserEx is very common) - AsyncRAT, QuasarRAT, and DcRAT are open-source — compare against public source code - Mutex names are excellent IOCs as they're usually unique per builder configuration - RAT builders are often leaked/cracked — the same RAT family may be used by many actors - Check Pastebin/Hastebin for C2 address delivery (AsyncRAT commonly uses this) - Remcos is sold as a "legitimate" remote admin tool — look for the SETTINGS resource - NjRAT is one of the oldest and most widely used — look for the `njq8` mutex pattern - Many RATs copy themselves to %AppData% or %Temp% with names mimicking system processes