@RussianPanda9xx Found some additional samples and wrote some quick capability to parse out information - pasted the results here: https://t.co/6QbQJnHlbb
@RussianPanda9xx@RussianPanda9xx - do you have a name for the PowerShell loader component that uses a "256-entry lookup table mapping 3-character tokens to byte values"?
@virusbtn FYSA, this DcRat is not DarkCrystalRAT, it is an open source project (https://t.co/WG1K1TymZj) that happens to share the same short name, where DarkCrystal refers to itself as DCRat (note case-typing)
@KrakenLabs_Team These samples are very different from the original reporting - the configuration uses a username/password for login "cracked" and "bydobroslavie". Also very strange that the classes/methods/fields have all been named as though it's been deobfuscated using de4dot
@CRDiegol@1ZRR4H@JAMESWT_WT Following the download chain, a final Base64 encoded payload is downloaded from (a too long url), payload is DcRat, configuration can be found at https://t.co/PM1xFj02SJ