{"id":1342,"date":"2023-04-16T06:38:49","date_gmt":"2023-04-16T06:38:49","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1342"},"modified":"2024-04-22T12:50:09","modified_gmt":"2024-04-22T12:50:09","slug":"trojan-win32-risepro","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2023\/04\/16\/trojan-win32-risepro\/","title":{"rendered":"Trojan.Win32.RisePro"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Trojan<\/p>\n<p><strong>Destruction Level:<\/strong> Medium<\/p>\n<p><strong>Prevalence:<\/strong> Medium<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Malware name(s)<\/strong><\/h3>\n<ul>\n<li>Trojan.Win32. RisePro.a (Padvish)<\/li>\n<li>A Variant Of Win32\/TrojanDownloader.Agent.GNV (ESET)<\/li>\n<li>HEUR:Trojan-PSW.Win32.RisePro (Kaspersky)<\/li>\n<\/ul>\n<h3><\/h3>\n<h3>What is a Trojan?<\/h3>\n<p>Trojans are a type of malware that masqurades themselves as legitimate and lawful software, behaving very similarly to useful and practical applications.<br \/>\nHowever, when executed, they create numerous disruptions for the system. In Some ways trojans enter a system including downloading software from the internet, embedding in HTML text, attaching to emails, and more.<br \/>\nUnlike computer viruses and worms, trojans cannot replicate themselves.<\/p>\n<h2><\/h2>\n<h2>What is RisePro malware?<\/h2>\n<p>The RisePro malware is a Trojan that collects system specs, browser logs, crypto wallet passwords, and screenshots of the victim and sends them to its command and control (C&amp;C) server.<br \/>\nAccording to the image published on the Telegram channel of this malware, this information is sold in full details. In addition, RisePro malware can receive malicious executable files from its C&amp;C server, including ransomwares and other malwares, to run on the victim&#8217;s system.<\/p>\n<p>&nbsp;<\/p>\n<h2>Technical Review<\/h2>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<p>Non-infected libraries used by the malware, located in a randomly named folder in the %Temp%path.<\/p>\n<p>Files like, Information.txt, passwords.txt, and other gathered information stored in a pseudorandomly-named folder in the %Temp%path (One of the two names has to be at least one character different from the othe).<\/p>\n<p>Internet connections in specified paths in the sent\/received commands table to C&amp;C servers.&#8221;<\/p>\n<p>&nbsp;<\/p>\n<h3>Performance Description<\/h3>\n<p>RisePro malware utilizes several un-infected libraries for its operations. To do so, it creates them in a folder within the %Temp%path upon execution.&#8221;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1344 alignnone\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/RisePro-1-1.png\" alt=\"\" width=\"665\" height=\"174\" \/><\/p>\n<p>Remote Server Connection<br \/>\nAfter collecting initial victim information, such as IP address and system specs, RisePro malware establishes communication with its C&amp;C server.<\/p>\n<p>Some command and control servers of this malware have the following structure:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1345\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/RisePro-2.png\" alt=\"\" width=\"523\" height=\"498\" \/><\/p>\n<p>Risepro malware commands include the followings:<\/p>\n<p>\/get_marks.php:<\/p>\n<p>List of the available services of the malware<br \/>\nfor presentation to its clients.<br \/>\nExamples of responses received from the server:<\/p>\n<p>{\u201csuccess\u201d:true,\u201dresult\u201d:<\/p>\n<p>{\u201cmarks\u201d:[{ \u201c_id\u201d:\u201dxxxx\u201d, \u201cuser\u201d:\u201dxxxx\u201d, \u201cname\u201d:\u201dBankiCA\u201d, \u201cdomains\u201d:\u201dbmo.com,cwbank.com,royalbank.com,vancity.com,servus.ca,coastcapitalsavings.com,alterna.ca,interiorsavings.com,synergycu.ca,mainstreetcu.ca\u201d, \u201ccolor\u201d:\u201dorange\u201d, \u201ccheckCookie\u201d:true, \u201ccheckPasswords\u201d:true, \u201ccheckHistory\u201d:false, \u201ccreatedAt\u201d:\u201d2023-01-26T08:49:30.239Z\u201d,\u201d__v\u201d:0},<br \/>\n{\u201c_id\u201d:\u201dxxxx\u201d,<\/p>\n<p>\u201cuser\u201d:\u201dxxxx\u201d, \u201cname\u201d:\u201dSetiXyeti\u201d, \u201cdomains\u201d:\u201d\/vpn\/index.html,portal\/webclient,remote\/login,\/vpn\/tmindex.html,\/LogonPoint\/tmindex.html,XenApp1\/auth\/login.aspx,auth\/silentDetection.aspx,\/citrix\/,\/RDWeb\/,\/+CSCOE+\/,\/global-protect\/,sslvpn.,\/dana-na\/,\/my.policy\u201d, \u201ccolor\u201d:\u201dpurple\u201d, \u201ccheckCookie\u201d:true, \u201ccheckPasswords\u201d:true, \u201ccheckHistory\u201d:true, \u201ccreatedAt\u201d:\u201d2023-01-26T08:48:59.868Z\u201d,\u201d__v\u201d:0},{\u201c_id\u201d:\u201dxxxx\u201d, \u201cuser\u201d:\u201dxxxx\u201d, \u201cname\u201d:\u201dkajabi.com\u201d, \u201cdomains\u201d:\u201dkajabi.com,newkajabi.com\u201d, \u201ccolor\u201d:\u201dred\u201d, \u201ccheckCookie\u201d:false, \u201ccheckPasswords\u201d:true, \u201ccheckHistory\u201d:false, \u201ccreatedAt\u201d:\u201d2022-12-04T17:23:31.450Z\u201d,\u201d__v\u201d:0},<br \/>\n{\u201c_id\u201d:\u201dxxxx\u201d,<\/p>\n<p>\u201cuser\u201d:\u201dxxxx\u201d, \u201cname\u201d:\u201dsteampowered.com\u201d, \u201cdomains\u201d:\u201dsteampowered.com\u201d, \u201ccolor\u201d:\u201dblue\u201d, \u201ccheckCookie\u201d:false, \u201ccheckPasswords\u201d:true, \u201ccheckHistory\u201d:false, \u201ccreatedAt\u201d:\u201d2022-12-04T14:57:23.380Z\u201d,\u201d__v\u201d:0},<br \/>\n{\u201c_id\u201d:\u201dxxxx\u201d,<\/p>\n<p>\u201cuser\u201d:\u201dxxxx\u201d, \u201cname\u201d:\u201dhumblebundle\u201d, \u201cdomains\u201d:\u201dhumblebundle.com\u201d, \u201ccolor\u201d:\u201dgreen\u201d, \u201ccheckCookie\u201d:true, \u201ccheckPasswords\u201d:true, \u201ccheckHistory\u201d:false, \u201ccreatedAt\u201d:\u201d2022-11-23T15:58:09.126Z\u201d,\u201d__v\u201d:0}]}}<\/p>\n<p>\u25ca \/get_settings.php:<\/p>\n<p>Get settings from the server<br \/>\nIn this command the list of information that needs to be collected from the victim system is specified.<\/p>\n<p>Examples of responses received from the server:<\/p>\n<p>{\u201csuccess\u201d:true,\u201dresult\u201d:<\/p>\n<p>{\u201csettings\u201d:{ \u201c_id\u201d:\u201dxxxx\u201d, \u201cHWIDduplicatesDay\u201d:true, \u201cHWIDduplicates\u201d:false, \u201cIPduplicates\u201d:false, \u201ctelegram\u201d:true, \u201cdiscord\u201d:true, \u201cscreenshot\u201d:true, \u201ccryptoWallets\u201d:true, \u201cnetHistory\u201d:true,<\/p>\n<p>\u201cstaticMarks\u201d:\u201d\u201d, \u201ctelegramIds\u201d:[], \u201ccreatedAt\u201d:\u201d2022-06-20T23:57:13.984Z\u201d,\u201d__v\u201d:0}}}<\/p>\n<p>\u25ca \/get_loader.php:<\/p>\n<p>According to the malware\u2019s code, this function is related to receiving the executable file and executing it with the ShellExecute function.<\/p>\n<p>\u25ca \/get_library.php:<\/p>\n<p>Get the non-infected libraries needed to run the malware&#8217;s features, if they are not statically present in the file.<\/p>\n<p>\u25ca \/set_file.php:<\/p>\n<p>Send the file from the victim&#8217;s system to the server.<\/p>\n<p>&nbsp;<\/p>\n<h3>Information Gathering<\/h3>\n<p>Once the type of information to be collected from the victim&#8217;s system is determined ( response to the &#8216;\/get_settings&#8217; query), RisePro gathers the information. The observed samples contain the following items:<\/p>\n<p>1. Hardware and software specs of the victim&#8217;s system.<br \/>\n2. Victim system specs, including the operating system, language, system time, hardware specs, list of processes, and a list of system softwares.<br \/>\nAfter collection, this information is stored in a text file named Information.txt.<\/p>\n<p>The malware obtains the victim&#8217;s IP address using the following addresses:&#8221;<\/p>\n<p>https:\/\/ipinfo.io<\/p>\n<p>https:\/\/db-ip.com<\/p>\n<p>https:\/\/www.maxmind.com\/en\/locate-my-ip-address<\/p>\n<p>The following image presents an example of information gathered by this malware:<\/p>\n<h2><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1346\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/RisePro-3.png\" alt=\"\" width=\"776\" height=\"588\" \/><\/h2>\n<h2><\/h2>\n<p>Victim&#8217;s Screenshot<br \/>\nBrowsers&#8217; information, password stored in crypto wallets, and some other softwares: In the observed examples, the targeted softwares of the malware included the following items:<br \/>\nBrowsers:<\/p>\n<p>Brave-Browser, CryptoTab Browser, Yandex, Atom, BlackHaw, Pale Moon, IceDragon,7Star, ChromePlus, Chromium, ChromiumViewer, Amigo, Chedot, Iridium, CentBrowser,Vivaldi, Elements Browser, Epic Privacy Browser, Citrio, Coowon, QIP Surf, Dragon, Orbitum,Torch, Comodo, 360Browser, Maxthon3, K-Melon, K-Meleon, Sputnik, Nichrome,CocCoc browser, NetboxBrowser, Firefox, Waterfox, Cyberfox, liebao, Kometa<\/p>\n<p>Crypto wallets:<\/p>\n<p>Terra, SaturnWallet, EQUALWallet, NiftyWallet, BitAppWallet, PaliWallet, NiftyWallet<br \/>\nLiqualityWallet, Iwallet, MewCx, ForboleX, Metamask , Coinbase, RoninWallet, CloverWallet<br \/>\nCloverWallet<\/p>\n<p>Other Softwares:<\/p>\n<p>Battle.net, NVIDIA GeForce Experience,<br \/>\nThunderbird, uCozMedia, Authenticator, Wombat, KardiaChain<\/p>\n<p>The information is stored in a file named passwords.txt, in which the name of the malware and its telegram address are included at the beginning.<\/p>\n<h2><\/h2>\n<h2><strong>How to deal with and clean t<\/strong><strong>he system?<\/strong><\/h2>\n<h2><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1347\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/01\/RisePro-4.png\" alt=\"\" width=\"961\" height=\"364\" \/><\/h2>\n<p>Padvish antivirus detects and removes this malware from the system.<br \/>\nTo prevent potential infection caused by this malware, it is recommended to avoid downloading files from unreliable sources that could lead to system infection.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan Destruction Level: Medium Prevalence: Medium &nbsp; Malware name(s) Trojan.Win32. RisePro.a (Padvish) A Variant Of Win32\/TrojanDownloader.Agent.GNV (ESET) HEUR:Trojan-PSW.Win32.RisePro (Kaspersky) What is a Trojan? Trojans are a type of malware that masqurades themselves as legitimate and lawful software, behaving very similarly to useful and practical applications. However, when executed, they create numerous disruptions for&hellip;<\/p>\n","protected":false},"author":21,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-1342","post","type-post","status-publish","format-standard","hentry","category-trojan"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1342"}],"version-history":[{"count":10,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1342\/revisions"}],"predecessor-version":[{"id":1547,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1342\/revisions\/1547"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}