{"id":1339,"date":"2023-10-07T06:03:47","date_gmt":"2023-10-07T06:03:47","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1339"},"modified":"2024-04-22T12:50:54","modified_gmt":"2024-04-22T12:50:54","slug":"virus-win32-expiro","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2023\/10\/07\/virus-win32-expiro\/","title":{"rendered":"Virus.Win32.Expiro"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Virus<\/p>\n<p><strong>Destruction Level:<\/strong> High<\/p>\n<p><strong>Prevalence:<\/strong> Low<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Malware nam<\/strong><strong>e(s)<\/strong><\/h2>\n<ul>\n<li>Virus.Win32.Expiro<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3>What is a virus?<\/h3>\n<p>In technical terms, a computer virus such as Expiro is a type of malware that cannot replicate itself automatically. Viruses can infect all accessible executable files in the computer system, which usually have .exe and .dll extensions. Viruses look for non-infected (host) files during execution and to replicate, they need to insert their own codes among the host file&#8217;s codes. Then, once the infected file is executed, the malicious code will be executed too.<\/p>\n<p>&nbsp;<\/p>\n<h2>Technical Review<\/h2>\n<p>The malware communicates with its malicious servers and sends them information about its version and the victim&#8217;s computer system specs.<br \/>\nThe purpose of this communication is sending information about the current version of the malware, the victim&#8217;s computer system specs and, if possible, receiving files from the malicious server.<br \/>\nThis information is encrypted before sending.<\/p>\n<p>&nbsp;<\/p>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<p>\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Existence of a data file, named \u201c%AppData%\u201d in the following path:<\/p>\n<p>\u201c%AppData%\\Roaming\\%s.bin\u201d<\/p>\n<p>\u00b7\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Sending information to numerous domains using POST method.<br \/>\nSome spotted domains are:<\/p>\n<p>pywolwnvd.biz<br \/>\nssbzmoy.biz<br \/>\ncvgrf.biz<br \/>\nnpukfztj.biz<br \/>\nprzvgke.biz<br \/>\nknjghuig.biz<br \/>\nfwiwk.biz<br \/>\ntbjrpv.biz<br \/>\ndeoci.biz<br \/>\nqaynky.biz<br \/>\nbumxkqgxu.biz<br \/>\ndwrqljrr.biz<br \/>\nytctnunms.biz<br \/>\noshhkdluh.biz<br \/>\njpskm.biz<br \/>\njhvzpcfg.biz<\/p>\n<p>&nbsp;<\/p>\n<h3>Performance Description<\/h3>\n<p>In the case that the services of the victim&#8217;s system, do not contain the following phrases, The Expiro virus infects the files corresponding to those services.<\/p>\n<p>windefend,\u00a0 TrustedInstaller, \u00a0UIodetect<\/p>\n<p>In addition to system services, it infects files with the extensions &#8220;exe.&#8221; and \u201cscr\u201d.<\/p>\n<p>The Virus behavior to infect system files is different<br \/>\nin the \u201cresurface\u201d and \u201cold\u201d variants, and is as follows:<\/p>\n<p>Older variant: Older variants of the Expiro virus remove part of the EP contents of<br \/>\nthe clean file and place it at the end of the last section.<br \/>\nThen it replaces its infected contents with the EP contents of the clean file and inserts its coded contents at the end of the file, after the EP information inserted from the clean file.<br \/>\nIt creates a .tmp file and write all this modified information inside it.<\/p>\n<p>The new variant: In the new variant of the Expiro virus, it writes its coded contents at the end of the last section of the clean file and then changes some attributes of the file in the \u201cPE Header\u201d, including \u201cSizeofRawData\u201d, \u201cChecksum\u201d, etc.<br \/>\nThis virus also rewrites a \u201ccall\u201d command in the clean file to execute its malicious codes when the infected file is executed. It does this in a way that instead of executing the clean function, it leads to the execution of the virus in the victim&#8217;s computer system.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>How to deal with and clean the system?<\/strong><\/h2>\n<p>By employing UMP technology as a part of its behavior-based protection, Padvish prevents the system from becoming infected through portable drives.<br \/>\nSo, by installing Padvish anti-malware\u00a0prevent\u00a0malware\u00a0infections (such as Expiro)<br \/>\nand make sure your device is not infected by them.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Virus Destruction Level: High Prevalence: Low &nbsp; Malware name(s) Virus.Win32.Expiro &nbsp; What is a virus? In technical terms, a computer virus such as Expiro is a type of malware that cannot replicate itself automatically. Viruses can infect all accessible executable files in the computer system, which usually have .exe and .dll extensions. Viruses&hellip;<\/p>\n","protected":false},"author":21,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23],"tags":[],"class_list":["post-1339","post","type-post","status-publish","format-standard","hentry","category-virus"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1339","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1339"}],"version-history":[{"count":9,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1339\/revisions"}],"predecessor-version":[{"id":1550,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1339\/revisions\/1550"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1339"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1339"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1339"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}