{"id":1081,"date":"2022-01-17T12:15:05","date_gmt":"2022-01-17T12:15:05","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1081"},"modified":"2024-02-14T11:52:57","modified_gmt":"2024-02-14T11:52:57","slug":"trojan-win32-andromeda","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2022\/01\/17\/trojan-win32-andromeda\/","title":{"rendered":"Trojan.Win32.Andromeda"},"content":{"rendered":"<h2 style=\"text-align: justify\">Overview<\/h2>\n<p style=\"text-align: justify\" align=\"left\"><strong>Type:<\/strong> Trojan<\/p>\n<p style=\"text-align: justify\" align=\"left\"><strong>Destruction Level:<\/strong> Moderate<\/p>\n<p style=\"text-align: justify\" align=\"left\"><strong>Prevalence:<\/strong>\u00a0High<\/p>\n<h3 style=\"text-align: justify\" align=\"left\">Malware names<\/h3>\n<p style=\"text-align: justify\" align=\"left\">\u2022 Trojan.Win32.Andromeda<br \/>\n\u2022 Downloader.Win32.Andromeda<\/p>\n<h3 style=\"text-align: justify\">What is a Trojan?<\/h3>\n<p style=\"text-align: justify\" align=\"justify\">Trojans are malware types that introduce themselves as healthy and legal software and act similarly to practical and applicable software but cause many destructions to the system when executing. The downloaded software from the internet, placing HTML text, attaching it to an email, etc. are ways that Trojans are using to enter the system. Contrary to viruses and computer worms, Trojans are not reproducible.<\/p>\n<h3 style=\"text-align: justify\" align=\"left\">What is Andromeda trojan?<\/h3>\n<p style=\"text-align: justify\" align=\"left\">Andromeda malware has the\u00a0nature of the bot that by connecting to the network and injecting code into the victim&#8217;s healthy processes, it can download and execute other malicious files, as well as it can steal information from the victim&#8217;s system and send it to specific servers.\u00a0This malware is a bot instance of the Gamarue malware suite.<\/p>\n<h2 style=\"text-align: justify\" align=\"left\">Technical information<\/h2>\n<h3 style=\"text-align: justify\" align=\"left\">Signs of infection<\/h3>\n<p>Symptoms of infection with this malware include the following:<\/p>\n<ol>\n<li>Injecting a malicious code in one of the following running processes and there is no Parent for these processes:\n<ul>\n<li>msiexec.exe<\/li>\n<li>svchost.exe<\/li>\n<li>wuauclt.exe<\/li>\n<\/ul>\n<\/li>\n<li>Existence of malware with random and volumetric names over 70 Mb, which is hidden in the following paths:<br \/>\n<code>%SystemDrive% \\ ProgramData<br \/>\n%AppData% \\ Roaming<\/code><\/li>\n<li>Existence of a file with &#8216;ms&#8217; letters that starts its operation in the following path:<br \/>\n<code>\u201c%SystemDrive%\\ProgramData\\Local Settings\\Temp\\ms**...**.exe\u201d<\/code><\/li>\n<li>The malware creates a copy of itself\u00a0winlogonr.exewhich is placed in the following path:<br \/>\n<code>\u201c%AppData%\\Roaming\\winlogonr\\winlogonr.exe\"<\/code><\/li>\n<\/ol>\n<h3>Describing Performance<\/h3>\n<p>In this section we will analyze two old and new versions of this malware:<\/p>\n<ul>\n<li>\n<h4>Performance_1<\/h4>\n<\/li>\n<\/ul>\n<p style=\"text-align: justify\" align=\"left\">This malware is a\u00a0http_based\u00a0bot that after infecting the system, it connects to the bot network. This bot is modular and if necessary, it downloads the module from its server and updates them.<\/p>\n<p style=\"text-align: justify\" align=\"left\">The malware file size is large and varies from sample to sample. The malware appears to have the ability to modify the contents of its files and\u00a070MB of it is useless content (according to the reviews during the analysis, it seems that the volume of the main content is only\u00a05KB approximately) This prevents it from being detected by antiviruses. On the other hand, due to its high volume, the malware cannot be detected and checked on analytics sites.<\/p>\n<p style=\"text-align: justify\" align=\"left\">The authors of the malware have made every effort to provide examples of this malware from packers and\u00a0decoder\u200cs and used different methods to make it difficult for antivirus to detect.<\/p>\n<p style=\"text-align: justify\" align=\"left\">Initially, the malware disables the &#8220;Windows error notifications&#8221;. It then checks the languages installed on the victim system. Below is a list of countries that Gamarure does not intend to run on their systems.<\/p>\n<ul style=\"text-align: justify\" type=\"disc\">\n<li>\n<p align=\"left\">Ukrainian<\/p>\n<\/li>\n<li>\n<p align=\"left\">Belarusian<\/p>\n<\/li>\n<li>\n<p align=\"left\">Kazakh<\/p>\n<\/li>\n<li>\n<p align=\"left\">Russian<\/p>\n<\/li>\n<\/ul>\n<p style=\"text-align: justify\" align=\"left\">Installed languages on the system will be checked in different parts of the program to prevent some malicious activities in Russian, Ukrainian, Belarusian, or Kazakhistanian. Malware uses Network Time Protocol (NTP)\u00a0to get the current time. To do this, it&#8217;s going to the NTP\u00a0domains\u00a0and receives the time, so, it starts from the first domain mentioned below and if it fails, it will continue its efforts with other domains.<\/p>\n<p style=\"text-align: justify\" align=\"left\">\u2022 north-america.pool.ntp.org<br \/>\n\u2022 south-america.pool.ntp.org<br \/>\n\u2022 asia.pool.ntp.org<br \/>\n\u2022 oceania.pool.ntp.org<br \/>\n\u2022 africa.pool.ntp.org<br \/>\n\u2022 north-america.pool.ntp.org<br \/>\n\u2022 pool.ntp.org<\/p>\n<ul>\n<li>\n<h4>Performance_2<\/h4>\n<\/li>\n<\/ul>\n<p>You can view the Andromeda process in the following image. This malware injects malicious codes inside the svchost.exe or wuauclt.exe processes.<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/01\/andromeda1.png\" \/><\/p>\n<p>Also, it can contain the following extensions:<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/01\/andromeda2.png\" \/><\/p>\n<p>In some paths, it also copies itself with a name containing &#8216;ms&#8217; letters:<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/01\/andromeda4.png\" \/><\/p>\n<p><code>\"AppData%\\Roaming\\winlogonr\\winlogonr.exe%\"<\/code><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/01\/andromeda5.png\" \/><\/p>\n<p align=\"left\">Registry changes:<\/p>\n<p align=\"left\">This malware performs changes in the registry to remain on the system so it can automatically operate after each OS boot.<\/p>\n<p><code>HKEY_LOCAL_MACHINE\\software\\microsoft\\windows nt\\currentversion\\windows<i><br \/>\n<\/i><i>Value Name: Load<\/i><i><br \/>\n<\/i><i>Value Data : %userprofile%\\Local Settings\\Temp\\ms&lt;%s&gt;.&lt;%s&gt;<\/i><\/code><\/p>\n<p>&nbsp;<\/p>\n<p dir=\"ltr\"><code>HKEY_LOCAL_MACHINE\\software\\microsoft\\windows\\currentversion\\Policies\\Explorer\\Run<i><br \/>\n<\/i><i>Value Name: &lt;%lu&gt;<\/i><i><br \/>\n<\/i><i>Value Data :%allusersprofile%\\Local Settings\\Temp\\ms&lt;%s&gt;.&lt;%s&gt;<\/i><\/code><\/p>\n<p dir=\"ltr\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/01\/andromeda6.jpg\" \/><\/p>\n<p dir=\"ltr\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/01\/andromeda7.jpg\" \/><\/p>\n<p dir=\"ltr\">Network connection:<\/p>\n<p dir=\"ltr\">This malware tries to connect with its C&amp;C which you can view its address in the following image:<\/p>\n<p dir=\"ltr\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/01\/andromeda8.jpg\" \/><\/p>\n<p dir=\"ltr\">The Andromeda transacted packets with its C&amp;C is as follows:<\/p>\n<ol>\n<li>first format:\n<ul>\n<li><u>\u201cid:%lu|bid:%lu|bv:%lu|sv:%lu|pa:%lu|la:%lu|ar:%lu\u201d<\/u><\/li>\n<li>Id: produced data from system file<\/li>\n<li>bid: defined constant value inside the bot<\/li>\n<li>bv: defined constant value inside the bot<\/li>\n<li>sv: the victim&#8217;s OS version<\/li>\n<li>pa: to assign if the OS is 32 or 64 bits<\/li>\n<li>la: produced value based on www.update.microsoft.com IP address<\/li>\n<li>ar: determines whether the bot is executed with admin privilege<img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/01\/andromeda9.png\" \/><\/li>\n<\/ul>\n<\/li>\n<li>Second format\n<ul>\n<li><i><u>id:%lu|tid:%lu|result:%lu<\/u><\/i><\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p style=\"padding-left: 60px\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/01\/andromeda10.png\" \/><\/p>\n<h2 style=\"text-align: justify\" align=\"left\">How to deal with it and disinfect the system<\/h2>\n<p style=\"text-align: justify\" align=\"left\"><a href=\"https:\/\/padvish.com\/fa-ir\/main\">Padvish Antivirus<\/a> detects this malware and removes it from the system. Padvish\u00a0Intrusion Prevention System (IPS) \u00a0prevents network attacks by this malware and its connection to your server. It also detects files downloaded by this malware. Therefore, to prevent infection with this malware, it is recommended to prevent malware from entering your system by installing Padvish.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan Destruction Level: Moderate Prevalence:\u00a0High Malware names \u2022 Trojan.Win32.Andromeda \u2022 Downloader.Win32.Andromeda What is a Trojan? Trojans are malware types that introduce themselves as healthy and legal software and act similarly to practical and applicable software but cause many destructions to the system when executing. The downloaded software from the internet, placing HTML text,&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-1081","post","type-post","status-publish","format-standard","hentry","category-trojan"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1081","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1081"}],"version-history":[{"count":18,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1081\/revisions"}],"predecessor-version":[{"id":1420,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1081\/revisions\/1420"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}