667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9ratonrat: 667f1f97d015 — .NET Framework 4.x full-spectrum RAT, HVNC + browser theft + ransomware module
Executive Summary
A 2.5 MB .NET Framework 4.x GUI PE32 labeled clientForCrypters.exe — a full-spectrum commodity RAT with Hidden VNC (HVNC), browser credential cloning via DPAPI + SQLite, keylogging, screen/webcam/mic capture, WiFi credential theft, process injection (RunPE), and modular ransomware/locker/screamer impact forms. Packaged with Costura.Fody IL merging. Ten confirmed siblings share identical internal naming. Static-only analysis (CAPE skipped — no Windows guest). ^[file.txt] ^[exiftool.json]
What It Is
| Attribute | Value |
|---|---|
| SHA-256 | 667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9 |
| File type | PE32 executable (GUI) Intel 80386 Mono/.NET assembly, 3 sections ^[file.txt] |
| Size | 2,508,288 bytes |
| Timestamp | Fri Nov 6 11:12:38 2048 UTC (fabricated future date) ^[pefile.txt:34] ^[exiftool.json:15] |
| Internal name | clientForCrypters.exe ^[exiftool.json:41] |
| Original filename | clientForCrypters.exe ^[exiftool.json:43] |
| VS_VERSIONINFO | FileDescription="Application", ProductName="Application", Copyright="Copyright © 2026" ^[exiftool.json:38-44] |
| Linker | Version 48.0 (non-standard; .NET IL assembler) ^[pefile.txt:45] |
| Build toolchain | .NET Framework 4.x, Costura.Fody 6.0.0.0 for IL merging ^[strings.txt:4119] |
| Signed | No ^[rabin2-info.txt:27] |
| Packing | None — plain .NET with embedded compressed dependencies ^[capa.txt:178] |
| Obfuscation | None observed — class/namespace names fully readable ^[strings.txt:7865-7871] |
| Family | ratonrat (medium confidence; 10 confirmed siblings share clientForCrypters.exe internal name) |
The clientForCrypters.exe name implies a builder-kit distribution model: a "crypter client" sold to other criminals who configure and deploy it. The Client.Shit.Packaged namespace and Raton branding (Spanish for "rat") suggest a Spanish-speaking or Latin American developer community. ^[strings.txt:4995] ^[strings.txt:6999]
How It Works
Core architecture. The binary is a self-contained .NET Framework GUI application whose dependencies are IL-merged into the main assembly via Costura.Fody. At runtime, embedded compressed DLLs are decompressed from .rsrc and loaded into the AppDomain. ^[capa.txt:178] Notable embedded libraries: AForge.Video.DirectShow (webcam), NAudio 2.3.0.0 (microphone/audio), Newtonsoft.Json 13.0.0.0 (C2 serialization), and a custom Stuff.dll helper (12,288 bytes). ^[strings.txt:4116-4129]
C2 and communication. The RAT acts as both TCP client and TCP server, with HTTP fallback for C2. Capa reports act as TCP client (4 matches), start TCP server (2 matches), create HTTP request, receive HTTP response, and send HTTP request with Host header. ^[capa.txt:160-158] No hardcoded C2 endpoints were recovered statically — configuration is likely runtime-loaded or embedded in an encrypted resource not visible in plaintext strings. The Client.Raton.Supervisor+<Run>d__14 and Client.Raton.Supervisor+<OpenConnection>d__16 async state-machine strings confirm an async/await C2 connection loop. ^[strings.txt:7865-7866]
Surveillance suite. Comprehensive victim monitoring: capture screenshot (5 matches) ^[capa.txt:151], log keystrokes via application hook and log keystrokes via polling (3 matches) ^[capa.txt:146-149], read clipboard data (2 matches) and write clipboard data (3 matches) ^[capa.txt:180-181], webcam capture via AForge.DirectShow (HasCamera, GetCamerasList, SendCameraList), ^[strings.txt:4855-7542] and microphone capture via NAudio (HasMicrophone, SendAudioSafe). ^[strings.txt:5645-5340] HVNC hidden desktop is explicitly present: HvncCommand, hvncThread, hvncThreadRunning, isDesktopCapturing, doHvnc. ^[strings.txt:5193-5984]
Credential and data theft. Browser credential cloning across all major browsers: CloneChrome, CloneFirefox, CloneEdge, CloneOpera, CloneOperaGX, CloneBrave — each with dedicated async handler state machines. ^[strings.txt:4278-4624] DPAPI is used for secret decryption (Raton.Helper.DPAPI, DecryptPassword, Shit.DPapi). ^[strings.txt:4712-6093] SQLite access for browser database reading (SqliteMasterEntry, SqlStatement, ReadCookies, EatCookies). ^[strings.txt:7771-6959] WiFi credential theft via WifiGrab. ^[strings.txt:4882]
Process injection and escalation. RunPE-style process hollowing is supported: HandleRunPE, DelegateVirtualAllocEx, DelegateWriteProcessMemory, SuspendThread, ResumeThread. ^[strings.txt:4690-7756] UAC bypass is handled by Commands.Handlers.UAC. ^[strings.txt:4645] Acquire debug privileges and enter debug mode in .NET are flagged by capa. ^[capa.txt:238-239]
Impact modules. Embedded .resources files reveal modular impact forms: Ransomware, LockScreen, InputBlock, Screamer, Jigsaw, WPro. ^[strings.txt:6936-6946] These are accompanied by EncryptFile, DecryptFile, Change the wallpaper, Hide the Windows taskbar, and Swap mouse buttons capabilities. ^[capa.txt:212-217] A Chat form and game forms (Snake, MineSweeper) are also present, suggesting taunting or distraction features. ^[strings.txt:6945-6942]
Persistence and evasion. Registry Run keys (persist via Run registry key (6 matches)) ^[capa.txt:275] and scheduled tasks (schedule task via schtasks (8 matches)) ^[capa.txt:277]. Anti-VM references targeting QEMU, VMware, VirtualBox, and Xen. ^[capa.txt:133-141] Anti-debug via CheckRemoteDebuggerPresent and WudfIsAnyDebuggerPresent. ^[capa.txt:131-133] Self-deletion (6 matches). ^[capa.txt:132] Windows Defender tampering via registry (disable Windows Defender features via registry on Windows). ^[capa.txt:264]
Decompiled Behavior
Radare2 analysis recovered 3,324 CIL methods. The entry point lands at method.Program.Main (0x4043d8), which bootstraps the WinForms GUI and initializes the Client.Raton.Supervisor async C2 loop. ^[rabin2-info.txt:2] Key async state machines observed:
Client.Raton.Supervisor+<Run>d__14— main C2 supervisor loop ^[strings.txt:7865]Client.Raton.Supervisor+<OpenConnection>d__16— TCP connection handshake ^[strings.txt:7866]Client.Raton.PacketSender+<Send>d__4— outbound packet dispatch ^[strings.txt:7867]Client.Raton.PacketReader+<Run>d__6— inbound packet processing ^[strings.txt:7868]Commands.HVNCHandler+<HandleCloneChrome>d__28through+<HandleCloneEdge>d__33— per-browser credential cloning ^[strings.txt:7855-7860]Commands.Handlers.HandleKeylogger+<KeyCaptureLoop>d__22— keystroke capture ^[strings.txt:7862]
The .NET type system is unobfuscated; all namespaces, classes, and method names are human-readable, confirming either an unprotected builder output or a developer unconcerned with static analysis.
C2 Infrastructure
No hardcoded IP addresses, domains, or URLs were recovered from static strings. The C2 endpoint is runtime-resolved, likely from:
- An encrypted configuration block loaded at startup
- A companion file or registry-staged config
- A hardcoded decryption routine with embedded ciphertext (not visible in plaintext strings)
The Client.Raton.Supervisor+<OpenConnection>d__16 async method and host/port compiler-generated fields (<host>5__2, <port>5__3) confirm the endpoint is assembled at runtime. ^[strings.txt:4451-4500]
Interesting Tidbits
- Builder-kit branding. The
clientForCrypters.exename andClient.Shit.Packagednamespace strongly suggest this is a commercial builder output sold to less-technical criminals — the kind who need a "client for crypters" to pair with their stub. ^[strings.txt:5879] ^[strings.txt:4995] - Future timestamp. The PE timestamp of November 2048 is impossible and serves as a crude anti-forensic measure, or simply a default from a misconfigured build environment. ^[pefile.txt:34]
- Fody marker.
clientForCrypters_ProcessedByFodyconfirms Costura.Fody 6.x was used to IL-merge all dependencies into a single deployable EXE. ^[strings.txt:7697] - Embedded games. The
.resourcessection contains game forms (Snake,MineSweeper,Chat) alongside ransomware and lock-screen forms, suggesting the builder includes "prank" or taunt modules. ^[strings.txt:6936-6946] - HVNC naming. The
HvncCommand/doHvncstrings use the industry-standard abbreviation for Hidden VNC — a technique for covert interactive desktop control without visible windows. ^[strings.txt:4898-4953] - No packing, no obfuscation. Despite the sophisticated feature set, the binary is completely unobfuscated. Every class, method, and namespace is readable. This is consistent with a builder kit where the buyer receives pre-compiled output rather than source code.
- Siblings span multiple OpenCTI labels. Ten confirmed siblings share the
clientForCrypters.exeinternal name, yet OpenCTI labels themratonrat,clipbanker, andnjrat. Thenjratlabel on sample3f434324is likely a false positive;clipbankermay reflect a feature-limited variant with clipboard hijacking emphasized.
How To Mess With It (Homelab Replication)
Toolchain: .NET Framework 4.7.2+ targeting x86, Visual Studio 2022 or VS BuildTools, Costura.Fody 6.x NuGet package.
Build recipe:
- Create a new .NET Framework WinForms project in C#.
- Install
Costura.FodyandFodyNuGet packages. - Add dependencies:
AForge.Video.DirectShow,NAudio,Newtonsoft.Json,System.Drawing. - Write async TCP client/server classes with
TcpClient/TcpListener. - Add browser credential cloning using
System.Data.SQLite+System.Security.Cryptography.ProtectedData(DPAPI). - Build in Release mode. Fody will embed and compress all dependencies into
.rsrc.
Verification: Run capa <reproducer.exe> and compare to this sample's capa.txt. You should see matching hits for act as TCP client, capture screenshot, log keystrokes, read clipboard data, create process in .NET, and embed dependencies as resources using Fody/Costura.
What you'll learn: How a commodity .NET RAT builder assembles a full-spectrum surveillance binary from open-source libraries, and how Costura.Fody changes the static-analysis surface by hiding DLL boundaries.
Deployable Signatures
YARA Rule
rule RatonRAT_Generic {
meta:
description = "RatonRAT .NET Framework RAT family — clientForCrypters variant"
author = "PacketPursuit SOC"
reference = "/intel/analyses/667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9.html"
date = "2026-08-08"
hash = "667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9"
strings:
$a1 = "clientForCrypters.exe" ascii wide
$a2 = "Client.Raton.Supervisor" ascii wide
$a3 = "Raton.Helper.DPAPI" ascii wide
$a4 = "Client.Shit.Packaged" ascii wide
$a5 = "HvncCommand" ascii wide
$a6 = "doHvnc" ascii wide
$a7 = "HandleCloneChrome" ascii wide
$a8 = "WifiGrab" ascii wide
$b1 = "costura.aforge.video.directshow.dll.compressed" ascii wide
$b2 = "costura.naudio.core.dll.compressed" ascii wide
$b3 = "costura.newtonsoft.json.dll.compressed" ascii wide
$b4 = "costura.stuff.dll.compressed" ascii wide
condition:
uint16(0) == 0x5A4D and
(2 of ($a*) or 2 of ($b*))
}
Behavioral Hunt Query (Sigma-like)
title: RatonRAT Process and Network Behavior
detection:
selection_process:
- Image|endswith: 'clientForCrypters.exe'
- CommandLine|contains: 'clientForCrypters'
selection_network:
- Initiated: true
- DestinationPort:
- 4444
- 5555
- 6666
- 7777
- 8888
- 9999
selection_registry:
- EventType: SetValue
- TargetObject|contains:
- '\\Software\\Microsoft\\Windows\\CurrentVersion\\Run'
- '\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce'
selection_file:
- TargetFilename|contains:
- '\\AppData\\Roaming\\'
- '\\AppData\\Local\\'
- '\\Temp\\'
- Image|endswith: 'clientForCrypters.exe'
condition: selection_process or (selection_network and selection_file) or selection_registry
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 667f1f97d015b53c367e228ccef93007fe58300260598afcc85ced93854159c9 |
Hash |
| SHA-256 | e8573e97c75bec4b9645f40c94a1f961971aa28444e3726564f4dda1312aac25 |
Sibling hash |
| SHA-256 | 58a919673d1c3d581fe9e14a437a94297a77cce098191c286d5021a2211d6130 |
Sibling hash |
| SHA-256 | 9f21280ec273b0581cf6b2ff6ca6852d479c161b0d208691c8e6e401ee11b216 |
Sibling hash |
| SHA-256 | da590d16a8738a6c5f055fffcdcb49870e088d37e040bf1fc1880cbf9b3faa51 |
Sibling hash |
| Internal filename | clientForCrypters.exe |
Static string |
| VS_VERSIONINFO | FileDescription="Application", InternalName="clientForCrypters.exe", Copyright="Copyright © 2026" | Version info |
| Costura marker | clientForCrypters_ProcessedByFody |
Build artefact |
| Embedded DLL | costura.stuff.dll.compressed |
Resource name |
| HVNC strings | HvncCommand, hvncThread, doHvnc |
Capability strings |
| Browser clone strings | CloneChrome, CloneFirefox, CloneEdge, CloneOpera, CloneBrave, CloneOperaGX |
Capability strings |
| Registry persistence | HKCU\Software\Microsoft\Windows\CurrentVersion\Run |
Persistence path |
| Schtasks persistence | schtasks /create |
Persistence mechanism |
Behavioral Fingerprint
This binary is a .NET Framework WinForms GUI executable with a large .rsrc section containing compressed embedded DLLs (Costura.Fody pattern). Upon execution, it initializes an async TCP client/server C2 loop (Client.Raton.Supervisor), enumerates browser credential stores via DPAPI + SQLite (CloneChrome, CloneFirefox, etc.), captures the screen via System.Drawing, logs keystrokes via application hooks or polling, hijacks the clipboard, and optionally launches a Hidden VNC desktop (HvncCommand). It persists via registry Run keys and scheduled tasks. The process makes outbound TCP connections within 30 seconds of launch and may spawn child processes via CreateProcessW with modified I/O handles for RunPE injection.
Detection Signatures
| MITRE ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys | capa persist via Run registry key (6 matches) ^[capa.txt:275] |
| T1053.005 | Scheduled Task/Job: Scheduled Task | capa schedule task via schtasks (8 matches) ^[capa.txt:277] |
| T1056.001 | Input Capture: Keylogging | capa log keystrokes via application hook, log keystrokes via polling (3 matches) ^[capa.txt:146-149] |
| T1113 | Screen Capture | capa capture screenshot (5 matches) ^[capa.txt:151] |
| T1115 | Clipboard Data | capa read clipboard data (2 matches), write clipboard data (3 matches) ^[capa.txt:180-181] |
| T1059 | Command and Scripting Interpreter | capa compile CSharp in .NET, compile Visual Basic in .NET ^[capa.txt:273-274] |
| T1620 | Reflective Code Loading | capa invoke .NET assembly method (2 matches), load .NET assembly (3 matches) ^[capa.txt:270-272] |
| T1497.001 | Virtualization/Sandbox Evasion: System Checks | capa reference anti-VM strings targeting QEMU/VMware/VirtualBox/Xen ^[capa.txt:133-141] |
| T1562.001 | Impair Defenses: Disable or Modify Tools | capa disable Windows Defender features via registry on Windows ^[capa.txt:264] |
| T1070.004 | Indicator Removal: File Deletion | capa self delete (6 matches) ^[capa.txt:132] |
| T1027 | Obfuscated Files or Information | capa Obfuscated Files or Information, Compile After Delivery ^[capa.txt:26-28] |
| T1213 | Data from Information Repositories | capa Data from Information Repositories ^[capa.txt:16] |
| T1087 | Account Discovery | capa Account Discovery ^[capa.txt:34] |
| T1083 | File and Directory Discovery | capa File and Directory Discovery ^[capa.txt:36] |
| T1012 | Query Registry | capa Query Registry ^[capa.txt:38] |
| T1518 | Software Discovery | capa Software Discovery ^[capa.txt:39] |
| T1082 | System Information Discovery | capa System Information Discovery ^[capa.txt:40] |
| T1016 | System Network Configuration Discovery | capa System Network Configuration Discovery ^[capa.txt:42] |
| T1033 | System Owner/User Discovery | capa System Owner/User Discovery ^[capa.txt:43] |
| T1129 | Shared Modules | capa Shared Modules ^[capa.txt:44] |
| T1047 | Windows Management Instrumentation | capa Windows Management Instrumentation ^[capa.txt:45] |
| T1496 | Resource Hijacking | capa Resource Hijacking ^[capa.txt:46] |
| T1134 | Access Token Manipulation | capa Access Token Manipulation ^[capa.txt:50] |
| T1095 | Non-Application Layer Protocol | capa act as TCP client (4 matches), start TCP server (2 matches) ^[capa.txt:160-161] |
References
- Artifact ID:
9a89d56d-e10f-4e81-9fcd-32b247b9bfbc - Source: OpenCTI connector (MalwareBazaar payload)
- Sibling analysis:
e8573e97c75bec4b9645f40c94a1f961971aa28444e3726564f4dda1312aac25(OpenCTI label:ratonrat) - Related wiki pages: ratonrat, costura-fody-il-merging, dotnet-hvnc-hidden-desktop, browser-credential-harvesting, raw-tcp-c2-socket
Provenance
file.txt— file(1) output, version unknownexiftool.json— ExifTool 12.76pefile.txt— pefile Python librarystrings.txt— GNU strings (7,893 lines)capa.txt— Mandiant capa v7.0.1 static analysisrabin2-info.txt— radare2 5.xrabin2 -Ibinwalk.txt— Binwalk v2.3.3floss.txt— FireEye flare-floss (errored; no decoded output)dynamic-analysis.md— CAPE sandbox skipped (no Windows guest available)- Radare2 analysis: 3,324 functions recovered from CIL, entry at
method.Program.Main