{"id":1132,"date":"2022-04-13T19:26:14","date_gmt":"2022-04-13T19:26:14","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1132"},"modified":"2024-01-17T12:14:50","modified_gmt":"2024-01-17T12:14:50","slug":"hacktool-win32-apt-ps","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2022\/04\/13\/hacktool-win32-apt-ps\/","title":{"rendered":"HackTool.Win32.APT- PS"},"content":{"rendered":"<p style=\"text-align: justify\">\t<div class=\"simple-alert-boxes sab_info sab_big \">\r\n\t\t\n<p style=\"text-align: justify\">Updated on 03-13-2022:<\/p>\n<p style=\"text-align: justify\">On 03-11-2022 AFTA Center released a warning related to this set of malware as &#8220;detecting a new malware in infrastructure&#8221; and called it the &#8220;Dilemma&#8221; which is the same HackTool.Win32.QWipe and you can read its complete analysis as follows.<\/p>\n<p style=\"text-align: justify\">Please refer to <a href=\"https:\/\/news.amnpardaz.com\/1401\/03\/5929\/%d8%a7%d8%b7%d9%84%d8%a7%d8%b9%db%8c%d9%87-%d9%be%d8%a7%d8%af%d9%88%db%8c%d8%b4-%d8%af%d8%b1%d8%a8%d8%a7%d8%b1%d9%87-%d8%b4%d9%86%d8%a7%d8%b3%d8%a7%db%8c%db%8c-%d8%a8%d8%af%d8%a7%d9%81%d8%b2%d8%a7\/\" target=\"_blank\" rel=\"noopener\">AFTA Center<\/a> to read the report.<\/p>\n<p style=\"text-align: justify\">\t<\/div>\r\n\t\n<h2 style=\"text-align: justify\">Technical details<\/h2>\n<h3 style=\"text-align: justify\">1.1 Modules and malware operation sequences<\/h3>\n<p style=\"text-align: justify\">This malware includes many modules, including executable programs and various scripts, each of which has its small task.<br \/>\nThe following is a list of malware files with a brief description of how they work.<\/p>\n<table style=\"border-collapse: collapse;width: 100%\" border=\"1\">\n<tbody>\n<tr style=\"height: 24px\">\n<td style=\"width: 50%;height: 24px\"><strong>File Name<\/strong><\/td>\n<td style=\"width: 50%;height: 24px\"><strong>Description<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td style=\"width: 50%;height: 48px\">HackTool.Win32.PS_Backdoor<\/td>\n<td style=\"width: 50%;height: 48px\">the malware Backdoor file is used to execute the hacker&#8217;s command and to download\/upload arbitrary files<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td style=\"width: 50%;height: 48px\">HackTool.Win32.QWipe<\/td>\n<td style=\"width: 50%;height: 48px\">Wiping Hard-disk data, changing users&#8217; passwords, deleting Windows backup files, etc.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 50%;height: 24px\">wint.bat<\/td>\n<td style=\"width: 50%;height: 24px\">Run the scheduler task to run the msdskint.exe file service<\/td>\n<\/tr>\n<tr style=\"height: 22px\">\n<td style=\"width: 50%;height: 22px\">Lastfile<\/td>\n<td style=\"width: 50%;height: 22px\">The contents of the last corrupted file path<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 50%;height: 24px\">HackTool.Win32.HttpBackdoor<\/td>\n<td style=\"width: 50%;height: 24px\">Act as\u00a0HttpBackdoor to create a backdoor in the system and execute the intruder&#8217;s commands<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td style=\"width: 50%;height: 48px\">HackTool.Win32.HttpCallBackService<\/td>\n<td style=\"width: 50%;height: 48px\">The intruder&#8217;s HttpCallBackService tool to establish a connection with C&amp;C servers<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 50%;height: 24px\"><span lang=\"af-ZA\">HackTool<\/span>.Win32.PS_Distributor<\/td>\n<td style=\"width: 50%;height: 24px\">Hacker&#8217;s\u00a0HttpBackdoor tool distribution file<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center\">Table 1 &#8211; Summary of malware payload performance<\/p>\n<h4 style=\"text-align: justify\">1.1.1 \u00a0Description of HackTool.Win32.PS_Backdoor threat performance<\/h4>\n<p style=\"text-align: justify\">This malware acts as a backdoor for the hacker. This file makes the remote command execution from the server possible for the hacker. Other features of this malware are it can download\/upload arbitrary files. The whole send\/receive data by this file happens through TLS packets.<\/p>\n<p style=\"text-align: justify\">This malware creates 4 execution sockets along with a local address on the victim&#8217;s system and then eavesdropping the data on these sockets. If receiving data, it will send them to its remote server using the below address. The malware uses port 8443 to connect with its remote server. This port like port 443 uses the TLS encryption method to transact packets. Currently, this server is offline.<\/p>\n<p style=\"text-align: justify\"><a href=\"http:\/\/Http:\/\/dropboxui[.]com:8443\">Http:\/\/dropboxui[.]com:8443<\/a><\/p>\n<p style=\"text-align: justify\">When using port 443, there&#8217;s no need to mention the port beside the domain address. But when using port 8443 it is necessary to note the port beside the domain address.<\/p>\n<p style=\"text-align: justify\">In the following, we will explain each socket&#8217;s performance.<\/p>\n<table style=\"border-collapse: collapse;width: 100%\" border=\"1\">\n<tbody>\n<tr style=\"height: 24px\">\n<td style=\"width: 50%;height: 24px\"><strong>Socket No.<\/strong><\/td>\n<td style=\"width: 50%;height: 24px\"><strong>Performance<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 120px\">\n<td style=\"width: 50%;height: 120px\">127.0.0.1:62563<\/td>\n<td style=\"width: 50%;height: 120px\">For receiving each TLS packet on this socket, the malware creates a cmd.exe process by recalling the main_startshell function and when executing, it will end the cmd.exe process and once again eavesdrop. It seems like the malware uses this socket only to receive execution commands.<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td style=\"width: 50%;height: 48px\">127.0.0.1:36774<\/td>\n<td style=\"width: 50%;height: 48px\">Receiving HTTP packets under TLS and recalling the main_starthttp function to download\/upload files.<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td style=\"width: 50%;height: 48px\">49151:[::] 0.0.0.0:49151<\/td>\n<td style=\"width: 50%;height: 48px\">Establishing a proxy server between this socket and the hacker&#8217;s remote server<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center\">Table 2- The malware sockets and their performance<\/p>\n<h4 style=\"text-align: justify\">1.1.2 wint.bat file performance<\/h4>\n<p style=\"text-align: justify\">This file executes the malware Wiper service. This is a service with a fake <strong>Windows Taks Scheduler <\/strong>name which you can see they&#8217;ve used the word <strong>Taks<\/strong> instead of <strong>Task. <\/strong>This\u00a0Wiper file has been seen on different systems through the following routes as msdskint.exe and Dilemma.exe:<\/p>\n<p style=\"text-align: justify\" align=\"left\"><strong>c:\\windows\\ccmcache\\6\\msdskint.exe<\/strong><\/p>\n<p style=\"text-align: justify\" align=\"left\"><strong>c:\\programdata\\pcmr\\msdskint.exe<\/strong><\/p>\n<h4 style=\"text-align: justify\" align=\"left\">1.1.3\u00a0<span lang=\"fa-IR\">HackTool.Win32.QWipe performance\u00a0<\/span><\/h4>\n<p style=\"text-align: justify\" align=\"left\">This file is the Wiper that the hacker created which can receive arguments. If there was no entry argument, the file has also contain predefined arguments which use them during execution.<\/p>\n<p style=\"text-align: justify\" align=\"left\">The hacker packed this file using the &#8220;<strong>Eziriz.NET Reactor<\/strong>&#8221; tool to obfuscate the malware codes from the analyzer and the antivirus. In the following, you can read how it acts after being decoded.<\/p>\n<p style=\"text-align: justify\" align=\"left\">In the following table, you can view a list of receivable arguments by the Wiper malware with their performance.<\/p>\n<table style=\"border-collapse: collapse;width: 100%\" border=\"1\">\n<tbody>\n<tr style=\"height: 24px\">\n<td style=\"width: 50%;height: 24px\"><strong>Entry arguments<\/strong><\/td>\n<td style=\"width: 50%;height: 24px\"><strong>Performance<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 48px\" width=\"26%\">-wipe-exclude<\/td>\n<td style=\"width: 50%;height: 48px\">The routes which are placed after this argument will be added to the malware exclusion list so they can be untouched during Wiping activity.<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 48px\" width=\"26%\">-light-wipe<\/td>\n<td style=\"width: 50%;height: 48px\">Times when malware buffer has been written on the victim&#8217;s system to execute wiping activity.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 24px\" width=\"26%\">-sessions<\/td>\n<td style=\"width: 50%;height: 24px\">It restarts and logs off all system active Sessions<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 24px\" width=\"26%\">-delete-users<\/td>\n<td style=\"width: 50%;height: 24px\">Deletes all entered user&#8217;s accounts with the argument itself<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 24px\" width=\"26%\">-shadows<\/td>\n<td style=\"width: 50%;height: 24px\">Wipes all system backup versions<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 24px\" width=\"26%\">-start-iis<\/td>\n<td style=\"width: 50%;height: 24px\">Restarts the iis service<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 24px\" width=\"26%\">-config<\/td>\n<td style=\"width: 50%;height: 24px\">Undefined activities<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 24px\" width=\"26%\">-processes<\/td>\n<td style=\"width: 50%;height: 24px\">Ends all entered process with the argument itself<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td style=\"width: 50%;height: 48px\" width=\"26%\">Logs-<\/td>\n<td style=\"width: 50%;height: 48px\">The malware wipes all OS and Event Viewer logs using Windows wevtutil.exe and Enum<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 48px\" width=\"26%\">-delete<\/td>\n<td style=\"width: 50%;height: 48px\">Finally, it removes all wiped files from the system, if enters this argument (it will execute\u00a0Win32Native.DeleteFile file)<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 24px\" width=\"26%\">-break-users<\/td>\n<td style=\"width: 50%;height: 24px\">Changes the victim&#8217;s system passwords<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 24px\" width=\"26%\">-wipe-only<\/td>\n<td style=\"width: 50%;height: 24px\">Wipes only the files on the entered routes<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 48px\" width=\"26%\">-purge<\/td>\n<td style=\"width: 50%;height: 48px\">It&#8217;s the complete removal and its wiping procedure is different than the normal procedure.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 50%;height: 24px\" width=\"26%\">-passwords<\/td>\n<td style=\"width: 50%;height: 24px\">Undefined activities<\/td>\n<\/tr>\n<tr>\n<td dir=\"ltr\" style=\"width: 50%\" width=\"26%\">-wipe-all<\/td>\n<td style=\"width: 50%;height: 24px\">Wiping all system drives<\/td>\n<\/tr>\n<tr>\n<td dir=\"ltr\" style=\"width: 50%\" width=\"26%\">-stop-iis<\/td>\n<td style=\"width: 50%\">Stoping iis service<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center\">Table 3- HackTool.Win32.QWipe malware performance<\/p>\n<ul style=\"text-align: justify\">\n<li><strong>-\u200cbreak.users argument<\/strong><\/li>\n<\/ul>\n<p style=\"text-align: justify\">If this is the entry argument and a user is specified, the malware sets a password for each defined account. This password is the permanent\u00a0<span lang=\"fa-IR\">\u201c<\/span>S7Y1a82R!\u201d string.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/2.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 1- changing user&#8217;s password by the malware<\/p>\n<ul style=\"text-align: justify\">\n<li><strong>-purge argument<\/strong><\/li>\n<\/ul>\n<p style=\"text-align: justify\">This argument is being used when the malware is wiping files. In general, the value that is considered for wiping data is a 200-byte buffer that its contents are created randomly through an algorithm.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/2.1.png\" \/><\/p>\n<p style=\"text-align: justify\">If a purge argument is entered, a full_purge value will be set inside the malware code. This Item is the complete wiping of the malware. In this situation, the wiping procedure is that it writes the buffer value on the file until reaches the end of the file.<\/p>\n<p style=\"text-align: justify\">Also, the malware contains a purgeExtensions list in its codes, including hackers&#8217; candidate suffixes. So if a file is about to be wiped then it must have one of the following suffixes and the wiping procedure will be the same as the full_purge procedure.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/3.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 2- Candidate suffixes<\/p>\n<p style=\"text-align: justify\">In addition to the above list, there are other strings inside the malware file that can be used as candidate suffixes which are as follows:<\/p>\n<pre>.accdb, .cdx, .dmp, .js, .pnf, .rom, .tif, .wmdb, .acl, .cfg, .doc, .hlp, .png, .rpt, .tiff, .wmv, .acm, .chk, .docx, .hpi, .lnk, .pps, .rsp, .tlb, .xdr, .amr, .com, .dot, .ppt, .sam, .tmp, .xls, .apln, .cpl, .drv, .pptx, .scp, .tsp, .xlsx, .asp, .cpx, .dwg, .hxx, .m4a, .pro, .scr, .avi, .dat, .eml, .ico, .mid, .psd, .sdb, .xsd, .ax, .db, .nls, .rar, .sig, .wab, .zip, .bak, .dbf, .ext, .one, .wab~, .bin, .dbx, .fdb, .jar, .pdf, .rdf, .sqlite, .wav, .bmp, .dll, .gif, .jpg, .pip, .resources, .theme, .wma, .config, .mxf, .mp3, .mp4, .cs, .vb, .tib, .aspx, .pem, .crt, .msg, .mail, .enc, .msi, .cab, .plb, .plt<\/pre>\n<ul style=\"text-align: justify\">\n<li><strong>-wipe-all argument\u00a0<\/strong><\/li>\n<\/ul>\n<p style=\"text-align: justify\">If this is the entry argument, then the whole system&#8217;s active drives will be restored inside a list. Then all dive information will be wiped.<\/p>\n<p style=\"text-align: justify\">Three files will be excluded when wiping information:<\/p>\n<ul style=\"text-align: justify\">\n<li><strong><span lang=\"af-ZA\">default.htm<\/span><\/strong><\/li>\n<li><strong><span lang=\"af-ZA\">index.htm<\/span><\/strong><\/li>\n<li><strong><span lang=\"af-ZA\">death_to_raisi.exe<\/span><\/strong><\/li>\n<\/ul>\n<p style=\"text-align: justify\">In the malware wiping procedure, when there is no set full_purge value nor file suffixes that are among candidate suffixes is that it firstly will write a value of 200 bytes from the defined buffer on the zero offset on the file. Then, the whole file size will be divided into 1024. Then it will restore this value inside the num4.<\/p>\n<p style=\"text-align: justify\">If there will be no entered value for the light_wipe argument, the minimum amount between light_wipe and num4 will be calculated and written on the num4.<\/p>\n<p style=\"text-align: justify\">Then it will distance 1024 bytes (0X40) from the offset on the num4 and then write that again on the next 200 bytes as well, so it will continue this pattern till the end of the file. In the end, it will create the lastfile2 file inside the wiped folder and writes the file route in the mentioned folder.<\/p>\n<p style=\"text-align: justify\">as we have mentioned before, the malware Wiper file if cannot receive any argument as an entry will use its predefined arguments. If this file is executed under the service then it will contain the following default arguments:<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/4.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 3- string list as the entry arguments<\/p>\n<p style=\"text-align: justify\">According to these arguments, this service will act as follows:<\/p>\n<p style=\"text-align: justify\">1- The -light-wipe value will be equal to 3. It means the data wiping buffer has been written 3 times on each file.<\/p>\n<p style=\"text-align: justify\">2- the iis service will be stopped.<\/p>\n<p style=\"text-align: justify\">3- it will delete all Windows Event Viewer logs.<\/p>\n<p style=\"text-align: justify\">4- It will delete all backup files<\/p>\n<p style=\"text-align: justify\">5- the -processes value will be equal to *sql. It means it ends all processes containing SQL strings in their names.<\/p>\n<p style=\"text-align: justify\">6- All active drive data except Exclude routs will be wiped<\/p>\n<p style=\"text-align: justify\">7- The excluded routes by the hacker are as follows:<\/p>\n<pre style=\"text-align: justify\">\"C:\\Windows\"\r\n\r\n\"C:\\$Recycle.Bin\"\r\n\r\n\"C:\\$WinREAgent\"\r\n\r\n\"C:\\Config.Msi\"\r\n\r\n\"C:\\MSOCache\"\r\n\r\n\"C:\\Recovery\"\r\n\r\n\"C:\\Program Files\\IBM\\*\"\r\n\r\n\"C:\\System Volume Information\"\r\n\r\n\"C:\\Program Files\\dotnet\"\r\n\r\n\"C:\\Program Files (x86)\\dotnet*\"\r\n\r\n\"C:\\Program Files\\Symantec*\"\r\n\r\n\"C:\\Program Files (x86)\\Symantec*\"\r\n\r\n\"C:\\Program Files (x86)\\Padvish*\"\r\n\r\n\"C:\\Program Files\\Kaspersky*\"\r\n\r\n\"C:\\Program Files (x86)\\Kaspersky*\"\r\n\r\n\"C:\\Program Files\\Microsoft*\"\r\n\r\n\"C:\\Program Files (x86)\\Microsoft*\"\r\n\r\n\"C:\\Program Files\\Windows*\"\r\n\r\n\"C:\\Program Files (x86)\\Windows*\"<\/pre>\n<p>There&#8217;s a function inside the malware commands that shows the hacker was sensitive to Padvish antivirus. For instance, as you can see the Figure 4, the malware monitored the list of executing processes on the victim&#8217;s system. If among processes, Padvish or its UI is executing, instead of executing the default functions for wiping information, the malware tries to use another method to wipe data.<\/p>\n<p style=\"text-align: justify\">It seems that the reason behind changing tactics from the malware is to evade the Padvish behavioral detection system which is detected the malware wiping method and immediately prevents it, but Padvish has also detected and prevented the other methods of the malware.<\/p>\n<p style=\"text-align: justify\">In the second method, the malware tries to create a temporary bat file (tmp.bat) for each system file and creates two temporary scheduling tasks with system permission for these files.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/5.png\" \/><\/p>\n<p style=\"text-align: center\">figure 4- The malware&#8217;s searching for Padvish antivirus UI and service<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/6.png\" \/><\/p>\n<p style=\"text-align: center\">figure 5- the malware changed its wiping method after finding the Padvish antivirus service<\/p>\n<p style=\"text-align: justify\">In the following, you can view an example of the created bat file<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/7.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 6- an example of created bat file to wipe data<\/p>\n<p style=\"text-align: justify\">As it is obvious from the bat file contents, firstly, the malware creates a file containing a null value equal to the file that was supposed to be wiped ( 3072 bytes) with the .qipe extension using Windows fsutil tool. Then it wanted to replace the original file with this fake file.<\/p>\n<p style=\"text-align: justify\">The hacker knew that Padvish could prevent this malware from wiping data, so it tried to use another method- using a system standard tool- to wipe data. nevertheless, the Padvish anti-ransomware component (Anti-Crypto) successfully prevent this attack.<\/p>\n<p style=\"text-align: justify\">There are commands inside the malware codes that indicate this malware can restore the run-time software logs when wiping as follows:<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/7.1.png\" \/><\/p>\n<p style=\"text-align: justify\">There are strings such as\u00a0\u00a0\u201c\u2013 Excluded\u201d \u060c \u201c\u2013 Skipped\u201d \u060c \u201cBreakSelectedUsers\u201d \u060c \u201cDeleteSelectedUsers\u201d \u060c \u201cKillProcesses\u201d, etc. This log ends with the &#8220;Finished on&#8221; string and records the end time when wiping is done. However, seems like the hacker needs not restore the log using the Wiper file because it did not consider a code for the Output function that has the duty of printing the result.<\/p>\n<h4 style=\"text-align: justify\">1.1.4\u00a0<span lang=\"af-ZA\">HackTool.Win32. HttpCallbackService performance\u00a0<\/span><\/h4>\n<p style=\"text-align: justify\">The hacker uses this file as a tool for downloading\/uploading files and executing arbitrary commands on the victim&#8217;s system. You can read the explanation of this performance below.<\/p>\n<p style=\"text-align: justify\">This file receives the information related to the malware server from its configuration file or the input.<\/p>\n<p style=\"text-align: justify\">In the following table you can see the commands that are supported by this tool:<\/p>\n<table style=\"border-collapse: collapse;width: 100%\" border=\"1\">\n<tbody>\n<tr>\n<td style=\"width: 20.1646%\"><strong>Command<\/strong><\/td>\n<td style=\"width: 79.8354%\"><strong>Performance<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1646%\">Download\/Upload<\/td>\n<td style=\"width: 79.8354%\">Encrypted downloading from the victim&#8217;s site or uploading files to the malware server and vice versa<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1646%\">stay-alive<\/td>\n<td style=\"width: 79.8354%\">activating isStayAliveMode flag<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1646%\">cool-down<\/td>\n<td style=\"width: 79.8354%\">Deactivating (for 1 minute) isStayAliveMode flag<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.1646%\">Default performance<\/td>\n<td style=\"width: 79.8354%\">Executing the hacker&#8217;s commands through the command line<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center\">Tabel 4-\u00a0HttpCallbackService too command list<\/p>\n<p style=\"text-align: justify\">In the following figures, you can see the complete scheme of the malware and its receivable queries.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/5-1.png\" \/><\/p>\n<p style=\"text-align: center\">figure 7-\u00a0HttpCallbackService malware function<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/6-1.png\" \/><\/p>\n<p style=\"text-align: center\">figure 8- list of strings and queries<\/p>\n<p style=\"text-align: justify\">First, the malware reads the hacker&#8217;s server address from the configuration file and according to the configuration file contents, the malware considers the following queries.<\/p>\n<table style=\"border-collapse: collapse;width: 100%\" border=\"1\">\n<tbody>\n<tr>\n<td style=\"width: 50%\"><strong>queries<\/strong><\/td>\n<td style=\"width: 50%\"><strong>the end string of the configuration file<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">=m?<\/td>\n<td style=\"width: 50%\">.aspx<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">=m?<\/td>\n<td style=\"width: 50%\">.php<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">=m<\/td>\n<td style=\"width: 50%\">\/<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 50%\">=m\/<\/td>\n<td style=\"width: 50%\">default<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center\">Table 5- strings and queries<\/p>\n<p style=\"text-align: justify\">The procedure of receiving commands from the server, for example, the malware server downloading a file from the client is that after connecting to the server, the contents of the file with the name of =m will be recalled from the server. Then after recovering the specified file route, the file will be encrypted using the base64 algorithm and will be sent to the server.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/7-1.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 9- Contents of the command file on the server-side<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/8-1.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 10- Encoding file using the malware and sending it to the malware server<\/p>\n<p style=\"text-align: justify\">If the =, the file contains a command, this command will b executed by cmd.exe<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/9.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 11- executing commands by cmd.exe<\/p>\n<p style=\"text-align: justify\">The malware executes its performance results inside a .out file on the victim&#8217;s system.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/10.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 12- The malware HttpCallbackService output log<\/p>\n<h4 style=\"text-align: justify\">1.1.5\u00a0<span lang=\"fa-IR\">HackTool.Win32.HttpBackdoor\u00a0<\/span><span lang=\"fa-IR\">performance\u00a0<\/span><\/h4>\n<p style=\"text-align: justify\">This file acts as an HTTP service for the hacker. The information related to the hacker&#8217;s arbitrary commands will be restored in two files: uhsvc.exe.start and uhscv.exe.ini. The name of this file was different in separate attacks.<\/p>\n<p style=\"text-align: justify\">This service which is registered as Microsoft Update Health Host inside the system contains commands to download\/upload files and also can connect to SQL database and send the results to the malicious server and manipulate local files. Different versions of the httpservice have been found: <strong>0.1.3vXH<\/strong> and <strong>0.1.4vXH<\/strong>. These versions are not different in performance and accept similar commands.<\/p>\n<p style=\"text-align: justify\">This file-like a hacker&#8217;s Wiper file packed using the \u201c<strong>Eziriz .NET Reactor<\/strong>\u201d tool. Additionally, in the malware configuration file, there are other commands as follows.<\/p>\n<table style=\"border-collapse: collapse;width: 100%\" border=\"1\">\n<tbody>\n<tr>\n<td style=\"width: 23.8683%\"><strong>Command<\/strong><\/td>\n<td style=\"width: 76.1317%\"><strong>Performance<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">ipcofig\/all<\/td>\n<td style=\"width: 76.1317%\">Recovering network card IP settings<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">whoami\/all<\/td>\n<td style=\"width: 76.1317%\">Recovering information related to username, user-group, permissions, and accesses<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">systeminfo<\/td>\n<td style=\"width: 76.1317%\">Total system information such as type of the OS, physical and virtual storage space, domain, network card, etc<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">tasklist<\/td>\n<td style=\"width: 76.1317%\">List of current processes<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">wmic logicaldisk get name<\/td>\n<td style=\"width: 76.1317%\">Names of the partitions of the disk<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">net user<\/td>\n<td style=\"width: 76.1317%\">User names of the current system<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">dir c:\\users<\/td>\n<td style=\"width: 76.1317%\">Displaying information related to files inside the c:\\users<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">net sessions<\/td>\n<td style=\"width: 76.1317%\">List of the current remote communications<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">net view\/all<\/td>\n<td style=\"width: 76.1317%\">List of the current shared sources<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">net share<\/td>\n<td style=\"width: 76.1317%\">List of shared drives and folders<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">route print<\/td>\n<td style=\"width: 76.1317%\">information related to Route tables<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">netstat-aon<\/td>\n<td style=\"width: 76.1317%\">Communication table related to active ports<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 23.8683%\">ping 8.8.8.8 -n 2<\/td>\n<td style=\"width: 76.1317%\">Checking the connection of the current system to the Internet<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center\">Table 6- Used commands inside the HttpBackdoor tool configuration file<\/p>\n<p style=\"text-align: justify\">The following results are attained after decoding according to the viewed issues:<\/p>\n<p style=\"text-align: justify\">1- The malware creates a tcpListener inside the victim&#8217;s system after is executed under the service. Then, we will explain one of the malware versions that use port 9399. In samples that are found from <strong>uhscv.exe.start,<\/strong> the hacker authorized the entry packets to port 9399 ( in some cases port 9396) in the firewall from out of the victim&#8217;s system network.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/8.png\" \/><\/p>\n<p style=\"text-align: center\">figure 13- uhsvc.exe.start file contents<\/p>\n<p style=\"text-align: justify\">2- The malware can receive and execute different commands from the hacker&#8217;s server. The malware executes these commands using the cmd tool.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/9.jpg\" \/><\/p>\n<p style=\"text-align: center\">Figure 14- Executing hacker&#8217;s arbitrary commands using shell<\/p>\n<p style=\"text-align: justify\">3- Using sqlConnection and sqlCommand functions to execute different queries on the SQL database<\/p>\n<p style=\"text-align: justify\">4- Creating file<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/10.jpg\" \/><\/p>\n<p style=\"text-align: center\">Figure 15- Creating file by the hacker using malware<\/p>\n<p style=\"text-align: justify\">5- The malware can zip or unzip the directories contents, download\/upload, and delete the hacker&#8217;s desired files, if necessary. This malware uses the IonicZip library to compress files.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/11.jpg\" \/><\/p>\n<p style=\"text-align: center\">Figure 16- Compressing\/ decompressing and removing files<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/12.jpg\" \/><\/p>\n<p style=\"text-align: center\">Figure 17- Manipulating directories contents<\/p>\n<p style=\"text-align: justify\">6- Capability to receive server desired proxies to connect with the server using =b and =p commands<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/13.jpg\" \/><\/p>\n<p style=\"text-align: center\">Figure 18- Commands related to proxy<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/14.jpg\" \/><\/p>\n<p style=\"text-align: center\">Figure 19- Setting proxy<\/p>\n<p style=\"text-align: justify\">7- Possibility of displaying the malware version for the hacker (the hacker used multiple versions of\u00a0HackTool.Win32.HttpBackdoor to implement his operation)<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/15.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 20- Displaying the malware version<\/p>\n<p style=\"text-align: justify\">8- Possibility of the current malware file route (\u201cc:\\programdata\\pcmr\\uhsvc.exe\u201d is the malware route).<\/p>\n<p style=\"text-align: justify\">9- Possibility of creating log files and sending them to show the possible errors to the hacker<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/16.jpg\" \/><\/p>\n<p style=\"text-align: center\">Figure 21- Creating a log file<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/17.jpg\" \/><\/p>\n<p style=\"text-align: center\">Figure 22- Log file<\/p>\n<p style=\"text-align: justify\">In the following table, you can see the operation that is supported by the malware:<\/p>\n<table style=\"border-collapse: collapse;width: 100%\" border=\"1\">\n<tbody>\n<tr>\n<td style=\"width: 20.2675%\"><strong>Command<\/strong><\/td>\n<td style=\"width: 79.7325%\"><strong>Performance<\/strong><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">a_1=s<\/td>\n<td style=\"width: 79.7325%\">Shellexecute with #zip support<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">a_1=c<\/td>\n<td style=\"width: 79.7325%\">Run SQL commands<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">a_1=i1<\/td>\n<td style=\"width: 79.7325%\">View output and error logs and delete them<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">a_1=i2<\/td>\n<td style=\"width: 79.7325%\">Delete output and error logs<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">a_1=i<\/td>\n<td style=\"width: 79.7325%\">Run cmd interactively<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">Cmd=<\/td>\n<td style=\"width: 79.7325%\">Shellexecute<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">W_i<\/td>\n<td style=\"width: 79.7325%\">Show Malware path<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">V_i<\/td>\n<td style=\"width: 79.7325%\">Show Malware Version<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">P=OR b=<\/td>\n<td style=\"width: 79.7325%\">Act as a proxy and forward connection to another website\/infected node<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">M=afe=1<\/td>\n<td style=\"width: 79.7325%\">\n<p>Write any file<\/p>\n<p>&nbsp;<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">Con=<\/td>\n<td style=\"width: 79.7325%\">Run SQL commands<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">Prt=<\/td>\n<td style=\"width: 79.7325%\">File Manager (Browse directories, Download\/Upload Files,&#8230;)<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 20.2675%\">other<\/td>\n<td style=\"width: 79.7325%\">Read\/Write based on GET<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center\">Table 7- Malware web service commands<\/p>\n<h4 style=\"text-align: justify\">1.1.6\u00a0HackTool.Win32.PS_Distributor Performance<\/h4>\n<p style=\"text-align: justify\">This file act as the distributor tool for the hacker. It has to establish connections with network clients and create and establish hackers&#8217; desired service and scheduled tasks. This file performs distributing tasks on the network.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/21.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 23- Starting distributor operation of the malware<\/p>\n<p style=\"text-align: justify\">This file use Share and &#8220;net use&#8221; command for its operation. As you can see in the above figure, this file contains a default username and password to connect with the clients:<\/p>\n<table style=\"border-collapse: collapse;width: 100%\" border=\"1\">\n<tbody>\n<tr>\n<td style=\"width: 100%\">\n<p style=\"text-align: justify\">Username : TicketUser<br \/>\nPassword: TicketUser<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: justify\">Additionally, this file can receive information such as username, password, and share folder route as an entry argument. Also, it can receive the list of its desired IP list from the distribiutor.ini.<\/p>\n<p style=\"text-align: justify\">The malware will copy the Httpservice tool as follows, after connecting with its desired clients:<\/p>\n<table class=\"table\" border=\"1\">\n<tbody>\n<tr>\n<td>\n<p class=\"western\" align=\"left\"><span lang=\"af-ZA\">\u201ccopy \/y c:\\\\windows\\\\msunify4.exe \\\\\\\\\u201d + ip +\u00a0<\/span><u><a href=\"https:\/\/%5C%5Cc%24%5C%5Cwindows%5C%5Cmsedgeupdate.exe\/\"><span lang=\"af-ZA\">\\\\c$\\\\windows\\\\msedgeupdate.exe<\/span><\/a><\/u><\/p>\n<p class=\"western\" align=\"left\"><span lang=\"af-ZA\">\u201ccopy \/y c:\\\\windows\\\\msunify.start \\\\\\\\\u201d + ip +\u00a0<\/span><u><a href=\"https:\/\/%5C%5Cc%24%5C%5Cwindows%5C%5Cmsedgeupdate.exe.start\/\"><span lang=\"af-ZA\">\\\\c$\\\\windows\\\\msedgeupdate.exe.start<\/span><\/a><\/u><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: justify\">As you can see from the above commands,\u00a0HackTool.Win32.HttpBackdoor tool named msunify4.exe exists in the current system. This file is copied into the destination system by the name of msedgeupdate.exe. msedgeupdate.exe file which is equal to msunify. the start is the configuration file of the above tool.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/22.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 24- Malware connecting network clients<\/p>\n<p style=\"text-align: justify\">Then the malware will create the following service:<\/p>\n<table class=\"table\" border=\"1\">\n<tbody>\n<tr>\n<td>\n<p class=\"western\" align=\"left\"><span lang=\"af-ZA\">\u201csc \\\\\\\\\u201d + ip + \u201d create \\\u201dMicrosoft Edge Update Service (edgeupdatel)\\\u201d binpath= \\\u201dc:\\\\windows\\\\msedgeupdate.exe\\\u201d start= auto\u201d<\/span><\/p>\n<p class=\"western\" align=\"left\">\u201csc \\\\\\\\\u201d + ip + \u201d start \\\u201dMicrosoft Edge Update Service (edgeupdatel)\\\u201d\u201d<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: justify\">As you can see, a\u00a0<span lang=\"fa-IR\">\u00a0<\/span>Microsoft Edge Update Service (edgeupdatel) service is created and executed inside the client for the msedgeupdate.exe file (HackTool.Win32.HttpBackdoor tool).<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/23.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 25- Creating and executing service on the clients<\/p>\n<p style=\"text-align: justify\">Then, the malware will create a scheduled task to execute the desired tool inside the clients.<\/p>\n<table class=\"table\" border=\"1\">\n<tbody>\n<tr>\n<td>\n<p class=\"western\" align=\"left\"><span lang=\"af-ZA\">\u201ccopy c:\\\\windows\\\\msunify.css \\\\\\\\\u201d + ip +\u00a0<\/span><u><a href=\"https:\/\/%5C%5Cc%24%5C%5Cusers%5C%5Cpublic%5C%5Ccreateservice.bat\/\"><span lang=\"af-ZA\">\\\\c$\\\\Users\\\\Public\\\\CreateService.bat<\/span><\/a><\/u><\/p>\n<p class=\"western\" lang=\"af-ZA\" align=\"left\"><span lang=\"af-ZA\">\u201cschtasks \/create \/S {0} \/tn \\\u201dBackup checks\\\u201d \/XML c:\\\\windows\\\\msunify4.xml \/U \\\u201d{1}\\\u201d \/P \\\u201d{2}\\\u201d \/F\u201d<\/span><\/p>\n<p class=\"western\" lang=\"af-ZA\" align=\"left\"><span lang=\"af-ZA\">\u201cschtasks \/run \/S {0} \/tn \\\u201dBackup checks\\\u201d \/U \\\u201d{1}\\\u201d \/P \\\u201d{2}\\\u201d\u201d<\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: justify\">The above commands show that the malware is copied a msunify.css file from the current system named CreateService.bat inside the client and on the c$\\\\Users\\Public\\\\. This file has to extract Nmap.exe to detect any security holes (flaws) in the network configurations. After recovering data, it will restore them inside the file named pse200.tmp. The following command shows the CreateService.bat file.<\/p>\n<table style=\"border-collapse: collapse;width: 100%\" border=\"1\">\n<tbody>\n<tr>\n<td style=\"width: 100%\">c:\\windows\\temp\\nmp\\nmap.exe -sV 200.200.0.0\/16 -oN C:\\windows\\temp\\pse200.tmp<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: justify\">Finally, the\u00a0HackTool.Win32.PS_Distributor tool will create a scheduled task named Backup Checks for the file msunify4.xml.<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/04\/24.png\" \/><\/p>\n<p style=\"text-align: center\">Figure 26- creating a scheduled task by\u00a0<span lang=\"fa-IR\">\u00a0<\/span>HackTool.Win32.PS_Distributor<\/p>\n<h2 style=\"text-align: justify\">2. How to encounter this malware<\/h2>\n<p style=\"text-align: justify\">All detected versions and types of this malware detected by <a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish Antivirus<\/a>\u00a0as\u00a0<strong>HackTool.Win32.HTTPbackdoor,<\/strong>\u00a0<strong><span lang=\"af-ZA\">HackTool.Win32.PS_Backdoo<\/span>r,<\/strong>\u00a0 <strong>HackTool.Win32.PS_Distributor<\/strong> ,\u00a0<strong>HackTool.Win32.HTTPCallBackService<\/strong> and\u00a0<strong>Trojan.Win32.QWipe.<\/strong><\/p>\n<p style=\"text-align: justify\">Additionally, the unique features of Padvish Data Protection with detecting the malware Wipe performance, preventing any data tampering, and putting an end to the malware execution.<\/p>\n<h2 style=\"text-align: justify\">3. Indicator of Compromise (IOC)<\/h2>\n<table style=\"border-collapse: collapse;width: 100%\" border=\"1\">\n<tbody>\n<tr style=\"height: 24px\">\n<td style=\"width: 491px;text-align: center;height: 24px\"><strong>File name<\/strong><\/td>\n<td style=\"width: 491px;text-align: center;height: 24px\"><strong>MD5<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 536px\">\n<td style=\"width: 491px;text-align: center;height: 536px\">\n<p dir=\"ltr\" align=\"center\">uhsvc.exe<\/p>\n<p align=\"center\"><span lang=\"af-ZA\">cbsvc.exe<\/span><\/p>\n<p align=\"center\"><span lang=\"af-ZA\">msunify.exe<\/span><\/p>\n<p align=\"center\"><span lang=\"af-ZA\">msunify4.exe<\/span><\/p>\n<p dir=\"rtl\" align=\"center\"><span lang=\"af-ZA\">msedgeupdate.exe<\/span><\/p>\n<\/td>\n<td style=\"text-align: center\">\n<p align=\"center\">466832ef3f81f1cc37466be9e1b7c4d2<\/p>\n<p align=\"center\">9fbab064ec583f80dc15e1abc2ebcad3<\/p>\n<p align=\"center\">2529ed634df912d95d52be717560b0b6<\/p>\n<p align=\"center\">cc97e34cf19f56263abd0f89e907cf7a<\/p>\n<p align=\"center\">66e6d3b03613074f38b2a6acff8e8229<\/p>\n<p align=\"center\">94354ecf588835cea2352b873211290e<\/p>\n<p align=\"center\">af029e3168e27394020b3f4315b2419b<\/p>\n<p align=\"center\">2c1e86a5c5c5ad19d64baa66e78af6f1<\/p>\n<p align=\"center\">e633f5ce289cdcbdee93b7c02178fa35<\/p>\n<p align=\"center\">4cc3665c4fb23ace6b0f9b396c66f8e6<\/p>\n<p align=\"center\">987a94bdce7f9d50fc0a30f2b10189f6<\/p>\n<p align=\"center\">1a773e123469ea5a22fd3c21b0de56e9<\/p>\n<p align=\"center\">c85af99a8c3bcb5826b9f938ba14d538<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 136px\">\n<td style=\"width: 491px;text-align: center;height: 136px\" height=\"9\">\n<p dir=\"ltr\" align=\"center\">uhsvc.exe.start<\/p>\n<p align=\"center\"><span lang=\"af-ZA\">msunify.start<\/span><\/p>\n<p align=\"center\"><span lang=\"af-ZA\">msedgeupdate.exe.start<\/span><\/p>\n<\/td>\n<td style=\"text-align: center\">\n<p align=\"center\">381d8239561c3714c1b71f0c2df4f57e<\/p>\n<p align=\"center\">798754303e774a09e5b0e7eff424fd7d<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 136px\">\n<td style=\"width: 491px;text-align: center;height: 136px\" height=\"9\">\n<p dir=\"ltr\" align=\"center\">uhsvc.exe.start<\/p>\n<p align=\"center\"><span lang=\"af-ZA\">msunify.start<\/span><\/p>\n<p align=\"center\"><span lang=\"af-ZA\">msedgeupdate.exe.start<\/span><\/p>\n<\/td>\n<td style=\"text-align: center\">\n<p align=\"center\">381d8239561c3714c1b71f0c2df4f57e<\/p>\n<p align=\"center\">798754303e774a09e5b0e7eff424fd7d<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 96px\">\n<td style=\"width: 491px;text-align: center;height: 96px\">\n<p align=\"center\"><span lang=\"af-ZA\">Msunify.css<\/span><\/p>\n<p align=\"center\"><span lang=\"af-ZA\">MSUnifySvc.bat<\/span><\/p>\n<\/td>\n<td style=\"text-align: center\">\n<p align=\"center\">eb08b4c7ecc25053e5fb23c200e7734b<\/p>\n<p align=\"center\">ff2253be230bb20fc68c3a1ad1107c72<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 216px\">\n<td style=\"width: 491px;text-align: center;height: 216px\">\n<p align=\"center\"><span lang=\"af-ZA\">wdisvc.exe<\/span><\/p>\n<p align=\"center\"><span lang=\"af-ZA\">spoolsvc.exe<\/span><\/p>\n<p align=\"center\"><span lang=\"af-ZA\">edgeupdatel.exe<\/span><\/p>\n<p align=\"center\"><span lang=\"af-ZA\">edgeupdaten.exe<\/span><\/p>\n<p align=\"center\"><span lang=\"af-ZA\">\u00a0<\/span><\/p>\n<\/td>\n<td style=\"text-align: center\">0ff024b1f42104ff0e9b22c38f293ad4<\/td>\n<\/tr>\n<tr style=\"height: 56px\">\n<td style=\"width: 491px;text-align: center;height: 56px\">\n<p align=\"center\"><span lang=\"af-ZA\">costura.ini<\/span><\/p>\n<\/td>\n<td style=\"text-align: center\">6cbc6bcc647bd8a8afb8384e95bc2fa1<\/td>\n<\/tr>\n<tr style=\"height: 80px\">\n<td style=\"width: 491px;text-align: center;height: 80px\">CDPSvc.bat<\/p>\n<p align=\"center\"><span lang=\"af-ZA\">\u00a0<\/span><\/p>\n<\/td>\n<td style=\"text-align: center\">\n<p align=\"center\">dafb3f2bce39562a68e6bd4176af6d86<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 56px\">\n<td style=\"width: 491px;text-align: center;height: 56px\">SpoolService.bat<\/td>\n<td style=\"text-align: center\">\n<p align=\"center\">beb00ea7a94fff2ce321a0e9377750ad<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 56px\">\n<td style=\"width: 491px;text-align: center;height: 56px\">CreateService.bat<\/td>\n<td style=\"text-align: center\">\n<p align=\"center\">03c3c225122414a94f90b2aedee490e9<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 56px\">\n<td style=\"width: 491px;text-align: center;height: 56px\">dao.exe<\/td>\n<td style=\"text-align: center\">\n<p align=\"center\">6319dfec18c53bfcd28cda698f03bd55<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 96px\">\n<td style=\"width: 491px;text-align: center;height: 96px\">\n<p dir=\"ltr\" align=\"center\">msdskint.exe<\/p>\n<p dir=\"ltr\" align=\"center\">Dilemma.exe<\/p>\n<\/td>\n<td style=\"text-align: center\">\n<p align=\"center\">13e7caebf00dd2315885e1f47030eb3c<\/p>\n<p align=\"center\"><span id=\"ctl04_ctl00_NVContentDescriptionContainer\">6d806a5b0390262b5ef4687ba10c540c<\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 80px\">\n<td style=\"width: 491px;text-align: center;height: 80px\">Distributor.exe<\/p>\n<p dir=\"ltr\" align=\"center\">\n<\/td>\n<td style=\"text-align: center\">\n<p align=\"center\">29841e0069749e1255269cdf4cf6e965<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 56px\">\n<td style=\"width: 491px;text-align: center;height: 56px\">Distributor.ini<\/td>\n<td style=\"text-align: center\">\n<p align=\"center\">2ee8f6d4853c59c2462ff0b71b455719<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 56px\">\n<td style=\"width: 491px;text-align: center;height: 56px\" height=\"10\">\n<p dir=\"ltr\" align=\"center\">wint.bat<\/p>\n<\/td>\n<td style=\"text-align: center\">0aa3b91d584803a39250742b69173841<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Technical details 1.1 Modules and malware operation sequences This malware includes many modules, including executable programs and various scripts, each of which has its small task. The following is a list of malware files with a brief description of how they work. File Name Description HackTool.Win32.PS_Backdoor the malware Backdoor file is used to execute the&hellip;<\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[48,50],"tags":[],"class_list":["post-1132","post","type-post","status-publish","format-standard","hentry","category-hacktool","category-apt"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1132"}],"version-history":[{"count":21,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1132\/revisions"}],"predecessor-version":[{"id":1185,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1132\/revisions\/1185"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}