{"id":1371,"date":"2024-01-21T05:59:16","date_gmt":"2024-01-21T05:59:16","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1371"},"modified":"2024-04-22T12:51:33","modified_gmt":"2024-04-22T12:51:33","slug":"worm-win32-renamer","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/01\/21\/worm-win32-renamer\/","title":{"rendered":"Worm.Win32.Renamer"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Worm<br \/>\n<strong>Destruction Level:<\/strong> Moderate<br \/>\n<strong>Prevalence:<\/strong> High<\/p>\n<h2><\/h2>\n<h3>Malware Name(s)<\/h3>\n<ul>\n<li>Worm.Win32.Renamer (Padvish)<\/li>\n<li>Virus:Win32\/Grenam.B (Microsoft )<\/li>\n<li>Win32\/AutoRun.Delf.LV (ESET-NOD32)<\/li>\n<\/ul>\n<h3><\/h3>\n<h3>What is a worm?<\/h3>\n<p>A worm is a type of malware characterized by its ability to self-replicate and spread within computer systems. Worms, like the Renamer malware, establish mechanisms for persistence, ensuring they remain active during each system boot. These malicious programs often spread through portable drives and shared directories within a network.<\/p>\n<h3><\/h3>\n<h3>What is the Renamer malware?<\/h3>\n<p>The <em>Renamer<\/em> malware, in particular, operates by generating its own files with deceptive names, closely resembling those of legitimate system files. After some alterations, the malware disguises itself among clean files, allowing it to execute alongside genuine components without raising immediate suspicion.<\/p>\n<h3><\/h3>\n<h2>Technical Review<\/h2>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<ol>\n<li>Adding a prefix (randomly) to the beginning of clean file names (in new versions letter (<strong>v<\/strong>) and in old versions letter (<strong>g<\/strong>)) and hiding them from the user<\/li>\n<li>Existance of the <span style=\"color: #3366ff\"><em>paint.exe<\/em><\/span> file, in the path <span style=\"color: #3366ff\"><em>Users%\\AppData\\Roaming\\Paint.exe%<\/em><\/span> (in the old version of <span style=\"color: #3366ff\"><em>Ground.exe<\/em><\/span>)<\/li>\n<li>Existence of the file <span style=\"color: #3366ff\"><em>systemroot%\\paint%<\/em><\/span><\/li>\n<li>Existence of <span style=\"color: #3366ff\"><em>Paint.lnk<\/em><\/span> file to guarantee survival:<br \/>\n<span style=\"color: #3366ff\"><em>%AppData%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Paint.lnk<\/em><\/span><br \/>\n<span style=\"color: #3366ff\"><em>Target: %AppData%\\Paint.exe<\/em><\/span><\/li>\n<\/ol>\n<h2><\/h2>\n<h3>Malware Intent<\/h3>\n<p>One of the goals of this malware is to occupy hard disk space and overuse CPU.<\/p>\n<p>&nbsp;<\/p>\n<h3>Performance Description<\/h3>\n<p>\u2714\ufe0f\u00a0Malware adds a random prefix (letter &#8220;<strong><span style=\"color: #ff6600\">v<\/span><\/strong>&#8221; in this version of the file ) to the beginning of the names of clean and system files in the following paths. Then it hides them and creates its own files with fake names, similar to the names of those files. In that way, the malware copies itself into folders.<br \/>\n<em><span style=\"color: #0000ff\">%systemroot%:\\*.exe<\/span><\/em><br \/>\n<em><span style=\"color: #0000ff\">%systemroot%:\\ProgramFiles\\\u2026\\*.exe<\/span><\/em><br \/>\n<em><span style=\"color: #0000ff\">:%Users%\\Desktop\\*.exe<\/span><\/em><\/p>\n<p>\u2714\ufe0f The system user runs the malware assuming the file is clean, but without realizing that first the malware and then the clean file is running. An example of how the malware works, can be seen in the following image:<\/p>\n<p><strong>Malware file:<\/strong> <span style=\"color: #0000ff\"><em>C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe<\/em><\/span><\/p>\n<p><strong>Clean file :<\/strong> <span style=\"color: #0000ff\"><em>C:\\Program Files\\Google\\Chrome\\Application\\<span style=\"color: #ff6600\">v<\/span>chrome.exe<\/em><\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1372 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2024\/02\/1-25d9258125d825a725db258c25d92584-25d825a825d825af25d825a725d9258125d825b225d825a725d825b1-1.jpg\" alt=\"\" width=\"824\" height=\"287\" \/><\/p>\n<p>\u2714\ufe0f\u00a0The malware places an autorun file with the following contents on all system drives <em>(%systemroot%: autorun.inf)<\/em> :<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-3795 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/01\/2-\u0628\u062f\u0627\u0641\u0632\u0627\u0631-\u0641\u0627\u06cc\u0644-autorun.png\" alt=\"\u0641\u0627\u06cc\u0644 autorun \u0628\u062f\u0627\u0641\u0632\u0627\u0631\" width=\"723\" height=\"274\" \/>\u2714\ufe0f\u00a0Then, for Survival, the Malware creates a shortcut that points to the original malware file:<\/p>\n<p><em><span style=\"color: #0000ff\">%Users%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Paint.lnk<\/span><\/em><br \/>\n<em><span style=\"color: #0000ff\">Target: %Users%\\AppData\\Roaming\\Paint.exe&#8221;<\/span><\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3796\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/01\/3-Shortcut-\u06a9\u0647-\u0628\u0647-\u0641\u0627\u06cc\u0644-\u0628\u062f\u0627\u0641\u0632\u0627\u0631-\u0627\u0635\u0644\u06cc-\u0627\u0634\u0627\u0631\u0647-\u0645\u06cc\u200c\u06a9\u0646\u062f.png\" alt=\"Shortcut \u06a9\u0647 \u0628\u0647 \u0641\u0627\u06cc\u0644 \u0628\u062f\u0627\u0641\u0632\u0627\u0631 \u0627\u0635\u0644\u06cc \u0627\u0634\u0627\u0631\u0647 \u0645\u06cc\u200c\u06a9\u0646\u062f\" width=\"698\" height=\"336\" \/><\/p>\n<h3><\/h3>\n<h2><strong>How to deal with and clean the system?<\/strong><\/h2>\n<p>\u2714\ufe0f\u00a0By employing <em>UMP<\/em> technology as a part of its behavior-based protection, Padvish antivirus prevents the system from becoming infected through portable drives.<br \/>\nSo, it is recommended to install Padvish antivirus to prevent malware infections (such as <em>Renamer<\/em>) that are transferred through portable drives.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Worm Destruction Level: Moderate Prevalence: High Malware Name(s) Worm.Win32.Renamer (Padvish) Virus:Win32\/Grenam.B (Microsoft ) Win32\/AutoRun.Delf.LV (ESET-NOD32) What is a worm? A worm is a type of malware characterized by its ability to self-replicate and spread within computer systems. Worms, like the Renamer malware, establish mechanisms for persistence, ensuring they remain active during each system&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-1371","post","type-post","status-publish","format-standard","hentry","category-worm"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1371","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1371"}],"version-history":[{"count":15,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1371\/revisions"}],"predecessor-version":[{"id":1553,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1371\/revisions\/1553"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1371"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1371"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1371"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}