{"id":104,"date":"2020-11-18T10:14:34","date_gmt":"2020-11-18T10:14:34","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=104"},"modified":"2023-02-07T07:17:25","modified_gmt":"2023-02-07T07:17:25","slug":"trojan-win32-racealer","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2020\/11\/18\/trojan-win32-racealer\/","title":{"rendered":"Trojan.Win32.Racealer"},"content":{"rendered":"<h2>General Explanation<\/h2>\n<p><strong>Type<\/strong>: Trojan<\/p>\n<p><strong>Degree of destruction<\/strong>: high<\/p>\n<p><strong>Prevalence<\/strong>: average<\/p>\n<h3>What is a Trojan?<\/h3>\n<p><span style=\"float: none;background-color: #ffffff;color: #333333;cursor: text;font-family: Georgia,'Times New Roman','Bitstream Charter',Times,serif;font-size: 16px;font-style: normal;font-variant: normal;font-weight: 400;letter-spacing: normal;text-align: left;text-decoration: none;text-indent: 0px\">Trojans are malware that revealed themselves in the format of an applicable and useful tool. Accordingly, the user downloads and installs them and infects the system without noticing that it is malware. Trojans, usually after installation, act as a backdoor so the hacker can remotely access the victim&#8217;s system. For instance, the malware we will analyze here seems to do an applicable and useful job, but it will install an unwanted application on the system.<\/span><\/p>\n<h3>What is Racealer malware?<\/h3>\n<p>Racealer or Raccoon stealer is malware that aims to steal information such as crypto-currency wallet on the system, browser data, and email will attempt to infect the victim\u2019s system.<\/p>\n<h2>Technical Explanation<\/h2>\n<h3 id=\"ipt_kb_toc_515_4\">Signs of infection<\/h3>\n<ul>\n<li>Download an empty file from google.drive:<\/li>\n<\/ul>\n<p style=\"padding-left: 60px\"><code>hxxps:\/\/drive[.]google[.]com\/uc?export=download&amp;id=\u2026<\/code><\/p>\n<ul>\n<li>Then it will connect with the command and control server and sends the request to the server-related IP in the following path with HTTP post protocol:<\/li>\n<\/ul>\n<p style=\"padding-left: 60px\"><code>hxxp:\/\/C&amp;C_IP\/gate\/log.php<\/code><\/p>\n<ul>\n<li>Also, sending requests to gate\/libs.zip and gate\/sqlite3.dl for receiving necessary files for extracting information.<\/li>\n<li>If the previous steps were not successful, it will send a request to the previous IP in the HTTP post:<\/li>\n<\/ul>\n<p style=\"padding-left: 60px\"><code>hxxp:\/\/C&amp;C_IP\/file_handler\/file.php<\/code><\/p>\n<p><strong>Introduction of the function:<\/strong><\/p>\n<p>The goal of this malware is to steal information from the system and it\u2019s not looking for permanence on the system; as a result, it will not stay in the system and has no considerable impact. Stolen information by this malware is stored information in browsers, clients\u2019 emails, and crypto-currency wallets. This malware uses Google services such as google drive to connect with the command and control server and find its IP. First, a part of its header will find its command and control server IP, by sending a request to a link in google drive and decrypting it, which usually, this server is behind google services. For hiding and not being detected, it will immediately change these links and IPs for being different for every attack. Then it will send general information about victims such as botID and system information to the attained IP in the gate\/log.php path. Then it will receive the necessary files to extract information from the system such as browsers, by connecting to gate\/sqlite3.dll and gate\/libs.zip addresses. In the end, it will send the stolen information to hxxp:\/\/C&amp;C_IP\/file_handler\/file.php. Usually, the distribution method of this malware is post-exploitation type, for instance, attackers run this malware in the victim\u2019s system by using exploit kits and existent vulnerabilities in browsers. Additionally, in some cases, they will distribute malware by phishing or social engineering.<\/p>\n<p><strong>Stolen information by Racealer malware:<\/strong><\/p>\n<ul>\n<li>The stored information in all browsers such as account names and stored passwords.<\/li>\n<li>Crypto-currency wallet data<\/li>\n<li>Client\u2019s emails data such as Thunderbird and Outlook<\/li>\n<\/ul>\n<h2 id=\"ipt_kb_toc_515_7\">How to deal with it and disinfect the system<\/h2>\n<p>To make sure that the system is safe, install <a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish antivirus<\/a> and keep its database file and scan it. Padvish IPS are often detected system OS vulnerabilities and secures them against this kind of attack. To prevent this kind of malware to enter the system, it is recommended to avoid clicking on suspicious links or scan the attached files of your email with an anti-virus. Also, always keep your OS, anti-virus, and browsers up to date, and stop using Internet Explorer and especially older versions, if possible, because these browsers have many vulnerabilities.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>General Explanation Type: Trojan Degree of destruction: high Prevalence: average What is a Trojan? Trojans are malware that revealed themselves in the format of an applicable and useful tool. Accordingly, the user downloads and installs them and infects the system without noticing that it is malware. Trojans, usually after installation, act as a backdoor so&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-104","post","type-post","status-publish","format-standard","hentry","category-trojan"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/104","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=104"}],"version-history":[{"count":6,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/104\/revisions"}],"predecessor-version":[{"id":1232,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/104\/revisions\/1232"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=104"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=104"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=104"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}