{"id":1086,"date":"2021-12-01T12:17:37","date_gmt":"2021-12-01T12:17:37","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1086"},"modified":"2024-02-14T11:49:56","modified_gmt":"2024-02-14T11:49:56","slug":"hacktool-win32-xwo-a","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2021\/12\/01\/hacktool-win32-xwo-a\/","title":{"rendered":"Hacktool.Win32.Xwo.a"},"content":{"rendered":"<h2 style=\"text-align: justify\">Overview<\/h2>\n<p style=\"text-align: justify\"><strong>Type:<\/strong> Hacktool<\/p>\n<p style=\"text-align: justify\"><strong>Destruction Level:<\/strong> High<\/p>\n<p style=\"text-align: justify\"><strong>Prevalence:<\/strong> Low<\/p>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify\">What is Hacktool?<\/h3>\n<p style=\"text-align: justify\">Hacktools are tools designed to facilitate intrusion. These tools can be used by a hacker to siphon data from the victim organization&#8217;s network. These tools are commonly used to retrieve the validation information of sensitive victim servers. For example, a hacker can use tools to guess passwords using Hacktool based on Brute Force attacks. In some cases, to increase access levels and exploit existing vulnerabilities, HackTools are used. In general, hacking tools can crash the computer and network security barriers and provide various capabilities to infiltrate systems.<\/p>\n<h3 style=\"text-align: justify\">What is Xwo malware?<\/h3>\n<p style=\"text-align: justify\">Xwo Is a Python-based robot that utilizes default web services and scans passwords in the ftp \u060cmysql \u060cpostgresql \u060cmongodb \u060credis \u060cmemcached \u060cTomcat \u060cphpMyAdmin \u060cVNC And RSYNC forms. The name of this tool is derived from the name of its main module. Xbash and MongoLock malware use this Hacktool as a tool to extract information. After finding the desired passwords, the malware sends them to its Commands and Control Server.<\/p>\n<h2 style=\"text-align: justify\">Technical Explanation<\/h2>\n<p style=\"text-align: justify\">MongoLock ransomware attacks MongoDB servers and extorts users to retrieve the data. Xwo And MongoLock Both use the same Python-based code and overlap in C2 infrastructure. Unlike MongoLock, the Xwo tool has no ransomware capability but sends the stolen information to its C2 server.<\/p>\n<h3 id=\"ipt_kb_toc_946_4\">Signs of infection<\/h3>\n<p style=\"text-align: justify\">Signs of infection include network connections. The malware is trying to connect to the following addresses:<br \/>\n\u2022 s [.] propub3r6espa33w [.] tk<br \/>\n\u2022 s [.] Blockchainbdgpzk [.] Tk<br \/>\n\u2022 s [.] Pcrisk [.] Xyz<br \/>\n\u2022 s [.] Rapid7 [.] Xyz<\/p>\n<h3 style=\"text-align: justify\">Description<\/h3>\n<p style=\"text-align: justify\">This tool first scans the network range provided by the command and control server. It then begins to gather information. First, it requests an HTTP POST with a User-Agent from a random list of coded options. This scanner uses encrypted code to obtain a list of command and control servers:<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2021\/11\/1-1.png\" alt=\"1-Hacktool.Win32.Xwo.a\" \/><\/p>\n<p style=\"text-align: justify\">Xwo aimed to check default passwords in MySQL \u060cPostgreSQL \u060cMongoDB \u060cRedis and Memcached databases. As shown in the image below, the code of this tool contains a dictionary of weak and known passwords so that if the user&#8217;s password matches one of them, it will send it to the server.<\/p>\n<h4 style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1088\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2022\/02\/Screenshot-from-2022-02-01-13-35-59.png\" alt=\"\" width=\"638\" height=\"456\" \/><\/h4>\n<p style=\"text-align: justify\">If it finds an Apache Tomcat scanner in the system, it uses a module to check for improper configuration and default passwords. Additional information such as default routes SVN \u060cGit and backups are also collected.<br \/>\nExample of validation test modules for tomcat:<\/p>\n<h4 style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1089\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2022\/02\/Screenshot-from-2022-02-01-13-36-13.png\" alt=\"\" width=\"679\" height=\"397\" \/><br \/>\nList of ports used for targeted malware:<\/h4>\n<p style=\"text-align: justify\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2021\/11\/4444.png\" alt=\"4-Hacktool.Win32.Xwo.a\" \/><\/p>\n<h2 style=\"text-align: justify\">How to deal with it and disinfect the system<\/h2>\n<p style=\"text-align: justify\"><a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish Antivirus<\/a> detects this malware and removes it from the system. Also, some policy implementations can prevent these attacks to the maximum. The most critical security measures to be taken in any network are as follows:<\/p>\n<ul>\n<li style=\"text-align: justify\">Update antivirus and review intrusion reports regularly<\/li>\n<li style=\"text-align: justify\">One of the ways this malware infiltrates is to take advantage of non-compliance with the necessary security policies regarding databases. Therefore, it is recommended to take the following measures seriously:\n<ul>\n<li style=\"text-align: justify\">Change the default username and password immediately after installing the databases<\/li>\n<li style=\"text-align: justify\">Lock accounts that are not in use. Remove them if you are sure you will never use them again.<\/li>\n<li style=\"text-align: justify\">Use strong passwords<\/li>\n<li style=\"text-align: justify\">Delete unused accounts as well as delete public access from all accounts<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Hacktool Destruction Level: High Prevalence: Low &nbsp; What is Hacktool? Hacktools are tools designed to facilitate intrusion. These tools can be used by a hacker to siphon data from the victim organization&#8217;s network. These tools are commonly used to retrieve the validation information of sensitive victim servers. For example, a hacker can use&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[48],"tags":[],"class_list":["post-1086","post","type-post","status-publish","format-standard","hentry","category-hacktool"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1086","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1086"}],"version-history":[{"count":7,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1086\/revisions"}],"predecessor-version":[{"id":1417,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1086\/revisions\/1417"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1086"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1086"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}