{"id":1300,"date":"2023-01-01T12:14:03","date_gmt":"2023-01-01T12:14:03","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1300"},"modified":"2024-02-14T11:45:31","modified_gmt":"2024-02-14T11:45:31","slug":"trojan-vbs-neoreklami","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2023\/01\/01\/trojan-vbs-neoreklami\/","title":{"rendered":"Trojan.VBS.Neoreklami"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type<\/strong>: Trojan<\/p>\n<p><strong>Degree<\/strong> <strong>of<\/strong> <strong>destruction<\/strong>: Moderate<\/p>\n<p><strong>Prevalence:<\/strong> High<\/p>\n<h2><strong>What<\/strong> is a Trojan?<\/h2>\n<p>Trojans are malware types that introduce themselves as healthy and legal software and act similarly to practical and applicable software but cause many destructions to the system when executing. The downloaded software from the internet, placing HTML text, attaching it to an email, etc. are ways that Trojans are using to enter the system. Contrary to viruses and computer worms, Trojans are not reproducible<\/p>\n<h2>What is Trojan.VBS.Neoreklami malware?<\/h2>\n<p>Trojan.VBS.Neoreklami is a Trojan downloader that starts downloading all types of Trojans and adds them to the Windows Defender whitelist as soon as entering the system.<\/p>\n<h2>Technical explanation<\/h2>\n<h3>Sign of infection<\/h3>\n<p>There are several signs of infection as follows:<\/p>\n<ul>\n<li>A &#8220;.exe&#8221; file with a random name inside a folder with a random name in the <span style=\"color: #ff6600\">\\C:\\ Windows\\Temp<\/span><\/li>\n<li>Wsf files with random name inside a folder with random name in the<span style=\"color: #ff6600\"> \\C:\\ ProgramData<\/span><\/li>\n<li>Dll files with random names inside a folder with random names in the <span style=\"color: #ff6600\">\\C:\\Program Files (x86)<\/span> for 64 bits OS and<span style=\"color: #ff6600\"> \\C:\\Program Files<\/span> for 32 bits OS.<\/li>\n<li>Deactivating Windows Defender continuous protection by creating the following key:<\/li>\n<\/ul>\n<p>HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-time Protection<\/p>\n<p>And adding value 1 to DisableRealtimeMonitoring<\/p>\n<ul>\n<li>Excluding created files for Windows Defender by creating the following keys:<\/li>\n<\/ul>\n<p>HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows Defender\\ Exclusions\\Paths<\/p>\n<p>HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\ Exclusions\\Paths<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1326\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2023\/02\/21.jpg\" alt=\"\" width=\"505\" height=\"188\" \/><\/p>\n<ul>\n<li>Changing default performance for some specific malware by creating the following keys<\/li>\n<\/ul>\n<p>HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\WindowsDefender\\Threats\\ThreatIdDefaultAction<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1327\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2023\/02\/21-1.jpg\" alt=\"\" width=\"513\" height=\"261\" \/><\/p>\n<p>These values are some threat identification that is detected by Windows Defender and each shows a sign of different malware.<\/p>\n<p>For instance: 2147735503 identification relates to the Trojan:Script\/Wacatac.B!ml threat or 2147735735 identification relates to Trojan: Win32\/Casur.A!cl.<\/p>\n<p>It set the default performance value for each one of these threats on 6 which means it lets the detected threats perform.<\/p>\n<p>Multiple tasks with random names in the C:\\Windows\\System32\\Tasks that each has to run dll and wsf files by the malware. Their running times are after the user&#8217;s log-on time at specific hours during the day.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1328\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2023\/02\/21-2.jpg\" alt=\"\" width=\"583\" height=\"133\" \/><\/p>\n<p>Creating new extensions on Chrome, Opera, Firefox, and Microsoft Edge through Find-it.Pro name. The malware changes the browser&#8217;s home page to the following link:<\/p>\n<p><a href=\"https:\/\/find-it.pro\/?utm_source=distr_m\">https:\/\/find-it.pro\/?utm_source=distr_m<\/a><\/p>\n<h2><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1329\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2023\/02\/21-3.jpg\" alt=\"\" width=\"462\" height=\"221\" \/><\/h2>\n<h2>Performance<\/h2>\n<p>The malware creates a wsf formatted downloader file with obscured code.<\/p>\n<p>Then it will extract 2 addresses from these files that <a href=\"http:\/\/www[.]testupdate[.]info\/updates\/ya\/wrtzr_ytab_a_1\/win\/version.txt\">http:\/\/www[.]testupdate[.]info\/updates\/ya\/wrtzr_ytab_a_1\/win\/version.txt<\/a> contains the version value of the malware.<\/p>\n<p>The malware uses the second address to download an audio file that contains the embedded malicious code.<\/p>\n<p><a href=\"http:\/\/www[.]testupdate[.]info\/updates\/ya\/wrtzr_ytab_a_1\/win\/upgdate_e.jpg\">http:\/\/www[.]testupdate[.]info\/updates\/ya\/wrtzr_ytab_a_1\/win\/upgdate_e.jpg<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1330\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2023\/02\/21-4.jpg\" alt=\"\" width=\"581\" height=\"220\" \/><\/p>\n<p>After running the exe code and decoding its contents inside the memory, the deactivating of Windows Defender continuous protection will begin. View the path of decoded contents in the memory in the following figure.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1331\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2023\/02\/21-5.jpg\" alt=\"\" width=\"581\" height=\"67\" \/><\/p>\n<p>Then it extracts a code that is encoded with the base64 algorithm.<\/p>\n<p>Now, the malware creates a registry settings file \u201cRegistry. pol\u201d in \\C:\\Windows\\System32\\GroupPolicy\\Machine and adds the abovementioned extracted key content, then extracts a base64 code with the software contents.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1332\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2023\/02\/21-6.jpg\" alt=\"\" width=\"583\" height=\"160\" \/><\/p>\n<p>Then, it will run the first task with the following commands:<\/p>\n<p>schtasks \/CREATE \/TN \u201cgroomer\u201d \/SC once \/ST 00:08:28 \/F \/RU \u201canalysis\u201d \/TR \u201cpowershell -WindowStyle Hidden -EncodedCommand cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4AIABnAHAAdQBwAGQAYQB0AGUALgBlAHgAZQAgAC8AZgBvAHIAYwBlAA==\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1333\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2023\/02\/21-7.jpg\" alt=\"\" width=\"582\" height=\"250\" \/><\/p>\n<p>The mentioned task runs with &#8220;schtasks \/run \/I \/tn \u201cgrxOaQmer command.<\/p>\n<p>Also, the decoding result will be the task contents of the following command:<\/p>\n<p>Start-process -Window Style Hidden gpupdate.exe \/force<\/p>\n<p>Then, the created dll exclusion path codes will be added again to the Registry.pol file and creates a new task with the same above PowerShell contents and will be wiped off the system finally.<\/p>\n<p>Then, all related codes to these keys will be obscured and added to a wsf file, then the malware adds the find-it.pro extension to all four browsers on the system.<\/p>\n<p>Also, it extracts dll file contents and adds them to the mentioned paths. After that, it creates the related tasks to the mentioned dlls.<\/p>\n<p>Actually, in every \u201clog on\u201d attempt, each one of the dlls runs at a specific time to make the detection impossible for Windows Defender.<\/p>\n<h2>How to encounter and disinfect the system<\/h2>\n<p>Padvish Antivirus can detect and remove Neoreklami malware from your system. To prevent any system infection by these types of malware it is recommended to avoid clicking on suspicious links and scan all files before execution. Keep your antivirus and OS updated all the time.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan Degree of destruction: Moderate Prevalence: High What is a Trojan? Trojans are malware types that introduce themselves as healthy and legal software and act similarly to practical and applicable software but cause many destructions to the system when executing. The downloaded software from the internet, placing HTML text, attaching it to an&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-1300","post","type-post","status-publish","format-standard","hentry","category-trojan"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1300","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1300"}],"version-history":[{"count":5,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1300\/revisions"}],"predecessor-version":[{"id":1412,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1300\/revisions\/1412"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1300"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1300"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1300"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}