{"id":1376,"date":"2024-01-28T07:34:30","date_gmt":"2024-01-28T07:34:30","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1376"},"modified":"2024-04-22T12:49:47","modified_gmt":"2024-04-22T12:49:47","slug":"hacktool-win32-backdoordiplomacy","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/01\/28\/hacktool-win32-backdoordiplomacy\/","title":{"rendered":"Hacktool.Win32.BackdoorDiplomacy"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> HackTool<br \/>\n<strong>Destruction Level:<\/strong> High<br \/>\n<strong>Prevalence:<\/strong> Moderate<\/p>\n<h3><\/h3>\n<h3>Malware Name(s)<\/h3>\n<ul>\n<li>Hacktool.Win32.BackdoorDiplomacy (Padvish )<\/li>\n<li>Win32\/Korplug.A (Eset)<\/li>\n<li>Backdoor.Win32.Gulpix.ab (Kaspersky)<\/li>\n<li>Trojan:Win32\/Plugx.B (Microsoft )<\/li>\n<\/ul>\n<h3><\/h3>\n<h3>What is HackTool?<\/h3>\n<p>Hacktools are tools designed to facilitate intrusion. These tools can be used by an intruder to siphon data from the victim organization\u2019s network. These tools are commonly used to siphon the validation information of sensitive victim servers. For example, an intruder can use hacktools to guess passwords based on Brute Force attacks. In some cases, to escalate access levels and exploit existing vulnerabilities, hackTools are used. In general, hack tools can crash the computer and network security barriers and provide various capabilities to infiltrate systems.<\/p>\n<h3><\/h3>\n<h3>What is\u00a0<em>BackdoorDiplomacy <\/em>malware<em>?<\/em><\/h3>\n<p>BackdoorDiplomacy malware is classified as a Remote Access Tool (RAT), offering intruders the capability to take full control over a victim&#8217;s system. This sophisticated malware comprises a set of plugins that afford attackers an extensive array of features, including:<\/p>\n<ul>\n<li>Making modifications to files and folders<\/li>\n<li>Logging all keystrokes on the computer keyboard<\/li>\n<li>Capturing the victim&#8217;s screen<\/li>\n<li>Executing files or commands<\/li>\n<li>Accessing the database within the victim&#8217;s system and executing SQL queries on it<\/li>\n<\/ul>\n<h2><\/h2>\n<h2>Technical Review<\/h2>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<p>?The presence of the \\AllUsersProfile%\\SxS% directory including the following files:<\/p>\n<ul>\n<li>Nv.exe<\/li>\n<li>NvSmartMax.dll<\/li>\n<li>NvSmart.chm or data files with varying extensions<\/li>\n<li>Files featuring the .plg extension<\/li>\n<\/ul>\n<p>?Additionally, The presence of an Autorun service, along with an entry for the existing executable (.exe) file within the path of the malware files.<\/p>\n<h3><\/h3>\n<h3>Performance Description<\/h3>\n<p>BackdoorDiplomacy malware files often contain a malicious library file and a data file, which is actually a compact and obscure PE (exe. file). BackdoorDiplomacy malware uses a technique called DLL Hijacking to execute itself (Autorun), in which malicious files are placed next to a clean executable file. The malicious malware library file is loaded by the clean exe. file, and in this way the data file is also loaded in the memory, decompressed, and executed, which ultimately leads to the execution of the malicious operation of the malware.<br \/>\nA variant of this malware uses the legitimate Nv.exe file of the NVIDIA application to execute itself. Files related to this type of malware include the following:<\/p>\n<table style=\"border-collapse: collapse;width: 71.4823%;height: 124px\" border=\"1\">\n<tbody>\n<tr style=\"height: 24px\">\n<td style=\"width: 44.5046%;text-align: center;height: 24px\">File Name<\/td>\n<td style=\"width: 55.4954%;height: 24px;text-align: center\">Description<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 44.5046%;height: 24px;text-align: center\"><strong><em>Nv.exe<\/em><\/strong><\/td>\n<td style=\"width: 55.4954%;height: 24px;text-align: center\">Legitimate program associated with the NVIDIA application that inadvertently loads the malicious malware library file.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 44.5046%;height: 24px;text-align: center\"><em><strong>NvSmartMax.dll<\/strong> \u06cc\u0627\u00a0<strong>Max.dll<\/strong><\/em><\/td>\n<td style=\"width: 55.4954%;height: 24px;text-align: center\">Malicious library file of the BackdoorDiplomacy malware, designed to load and execute the data file.<\/td>\n<\/tr>\n<tr style=\"height: 10px\">\n<td style=\"width: 44.5046%;height: 10px;text-align: center\"><em><strong>NvSmart.chm<\/strong> \u06cc\u0627 <strong>Nv.mpc<\/strong><\/em><\/td>\n<td style=\"width: 55.4954%;height: 10px;text-align: center\">Pseudo-code file that, in reality, is a compressed and obscured PE file containing the primary operations of the BackdoorDiplomacy malware.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4><\/h4>\n<h4>Network Operation<\/h4>\n<p>After execution, BackdoorDiplomacy malware initiates communication with its command and control servers. The method of communication with the remote server is determined by the initial configuration of the malware, allowing for connectivity over TCP, UDP, ICMP, or HTTP protocols. Once connected to its designated server, the malware proceeds to execute the corresponding plugins based on commands received from the attacker. The following is a list of servers associated with this malware:<\/p>\n<p dir=\"ltr\"><span style=\"color: #0000ff\"><em>\u25aa\ufe0fpicture[.]efanshion[.]com<\/em><\/span><\/p>\n<p dir=\"ltr\"><span style=\"color: #0000ff\"><em>\u25aa\ufe0fmail[.]popanalysis[.]com<\/em><\/span><\/p>\n<p dir=\"ltr\"><span style=\"color: #0000ff\"><em>\u25aa\ufe0fdl-adobe[.]com<\/em><\/span><\/p>\n<h4><\/h4>\n<h4>Malware Plugins<\/h4>\n<p>As previously discussed, the BackdoorDiplomacy malware comprises a set of plugins, each serving a distinct purpose. The following table delineates the respective objectives and commands executable within each plugin, providing an illustrative overview of the malware&#8217;s functionality.<\/p>\n<table class=\"wikitable\" style=\"height: 2199px;width: 1130px\" width=\"1218\">\n<tbody>\n<tr style=\"height: 24px\">\n<th style=\"width: 109px;height: 24px;text-align: center\">Command<\/th>\n<th style=\"width: 155px;height: 24px;text-align: center\">Subcommand<\/th>\n<th style=\"width: 707px;height: 24px;text-align: center\">Function<\/th>\n<\/tr>\n<tr style=\"height: 176px\">\n<td style=\"width: 109px;height: 176px;text-align: center\"><strong style=\"text-align: center\">Option<\/strong><\/td>\n<td style=\"width: 155px;height: 176px;text-align: center\">\n<p>\u25aa\ufe0f0x2000<\/p>\n<p>\u25aa\ufe0f0x2001<\/p>\n<p>\u25aa\ufe0f0x2002<\/p>\n<p>\u25aa\ufe0f0x2003<\/p>\n<p>\u25aa\ufe0f0x2005<\/td>\n<td style=\"width: 707px;height: 176px;text-align: left\">\n<ul>\n<li>Locking (user&#8217;s system) workstation<\/li>\n<li>Force shutdown request<\/li>\n<li>Reboot the system<\/li>\n<li>System shutdown request (enables the user to perform activities before shutdown)<\/li>\n<li>Requesting to display the intruder&#8217;s desired messages on the screen<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 248px\">\n<td style=\"width: 109px;height: 248px;text-align: center\"><strong style=\"text-align: center\">Disk<\/strong><\/td>\n<td style=\"width: 155px;height: 248px;text-align: center\">\n<p>\u25aa\ufe0f0x3000<\/p>\n<p>\u25aa\ufe0f0x3001<\/p>\n<p>\u25aa\ufe0f0x3002<\/p>\n<p>\u25aa\ufe0f0x300A<\/p>\n<p>\u25aa\ufe0f0x3004<\/p>\n<p>\u25aa\ufe0f0x3007<\/p>\n<p>\u25aa\ufe0f0x300D<\/p>\n<p>\u25aa\ufe0f0x300C<\/p>\n<p>\u25aa\ufe0f0x300E<\/td>\n<td style=\"width: 707px;height: 248px;text-align: left\">\n<ul>\n<li>Request to count the number of drives<\/li>\n<li>Request to search for the desired file<\/li>\n<li>Request to recursively search the file<\/li>\n<li>Create a directory<\/li>\n<li>Request to read the file<\/li>\n<li>Request to write to the file<\/li>\n<li>Request to copy\/rename\/delete and move the desired file<\/li>\n<li>Create a new desktop and run a process in it<\/li>\n<li>Request for an &#8216;expanded environment string<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 152px\">\n<td style=\"width: 109px;height: 152px;text-align: center\"><strong>Screen<\/strong><\/td>\n<td style=\"width: 155px;height: 152px;text-align: center\">\n<p>\u25aa\ufe0f0x4000<\/p>\n<p>\u25aa\ufe0f0x4004<\/p>\n<p>\u25aa\ufe0f0x4005<\/p>\n<p>\u25aa\ufe0f0x4006<\/p>\n<p>\u25aa\ufe0f0x4100<\/td>\n<td style=\"width: 707px;height: 152px;text-align: left\">\n<ul style=\"text-align: start\">\n<li>Request remote capabilities for a desktop<\/li>\n<li>Send mouse events<\/li>\n<li>Send keyboard events<\/li>\n<li>Send CTRL-Alt-Delete<\/li>\n<li>Request to capture a screen shot at the moment<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 104px\">\n<td style=\"width: 109px;height: 104px;text-align: center\"><strong>Process<\/strong><\/td>\n<td style=\"width: 155px;height: 104px;text-align: center\">\n<p>\u25aa\ufe0f0x5000<\/p>\n<p>\u25aa\ufe0f0x5001<\/p>\n<p>\u25aa\ufe0f0x5002<\/td>\n<td style=\"width: 707px;height: 104px;text-align: left\">\n<ul style=\"text-align: start\">\n<li>Request to create a process<\/li>\n<li>Request to count running processes<\/li>\n<li>Terminate and kill a process<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 152px\">\n<td style=\"width: 109px;height: 152px;text-align: center\"><strong style=\"text-align: center\">Service<\/strong><\/td>\n<td style=\"width: 155px;height: 152px;text-align: center\">\n<p>\u25aa\ufe0f0x6000<\/p>\n<p>\u25aa\ufe0f0x6001<\/p>\n<p>\u25aa\ufe0f0x6002<\/p>\n<p>\u25aa\ufe0f0x6003<\/p>\n<p>\u25aa\ufe0f0x6004<\/td>\n<td style=\"width: 707px;height: 152px;text-align: left\">\n<ul style=\"text-align: start\">\n<li>Querying a service configuration<\/li>\n<li>Change the desired service configuration<\/li>\n<li>Request to start a service<\/li>\n<li>Request to control a service<\/li>\n<li>Request to delete a service<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 109px;height: 24px;text-align: center\"><strong style=\"text-align: center\">Shell<\/strong><\/td>\n<td style=\"width: 155px;height: 24px;text-align: center\">0x7002<\/td>\n<td style=\"width: 707px;height: 24px;text-align: left\">\n<ul style=\"text-align: start\">\n<li>Request to run CMD<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td style=\"width: 109px;height: 48px;text-align: center\"><strong style=\"text-align: center\">Telnet<\/strong><\/td>\n<td style=\"width: 155px;height: 48px;text-align: center\">0x7100<\/td>\n<td style=\"width: 707px;height: 48px;text-align: left\">\n<ul style=\"text-align: start\">\n<li>Request to start the Telnet service<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 224px\">\n<td style=\"width: 109px;height: 224px;text-align: center\"><strong>RegEdit<\/strong><\/td>\n<td style=\"width: 155px;height: 224px;text-align: center\">\n<p>\u25aa\ufe0f0x9000<\/p>\n<p>\u25aa\ufe0f0x9001<\/p>\n<p>\u25aa\ufe0f0x9002<\/p>\n<p>\u25aa\ufe0f0x9003<\/p>\n<p>\u25aa\ufe0f0x9004<\/p>\n<p>\u25aa\ufe0f0x9005<\/p>\n<p>\u25aa\ufe0f0x9006<\/p>\n<p>\u25aa\ufe0f0x9007<\/td>\n<td style=\"width: 707px;height: 224px;text-align: left\">\n<ul style=\"text-align: start\">\n<li>Enumerate available registry keys<\/li>\n<li>Create the desired key<\/li>\n<li>Delete the desired registry key<\/li>\n<li>Copy the desired registry key<\/li>\n<li>Count the values in a specific registry key<\/li>\n<li>Set a value for a registry key<\/li>\n<li>Delete a value of a key<\/li>\n<li>Enter a value for the value of a key<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 109px;height: 24px;text-align: center\"><strong>Nethood<\/strong><\/td>\n<td style=\"width: 155px;height: 24px;text-align: center\">0xA000<\/td>\n<td style=\"width: 707px;height: 24px;text-align: left\">\n<ul style=\"text-align: start\">\n<li>Request to count network resources<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 109px;height: 43px;text-align: center\"><strong style=\"text-align: center\">Portmap<\/strong><\/td>\n<td style=\"width: 155px;height: 43px;text-align: center\">0xB000<\/td>\n<td style=\"width: 707px;height: 43px;text-align: left\">\n<ul style=\"text-align: start\">\n<li>Command to initiate port mapping<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 104px\">\n<td style=\"width: 109px;height: 104px;text-align: center\"><strong style=\"text-align: center\">SQL<\/strong><\/td>\n<td style=\"width: 155px;height: 104px;text-align: center\">\n<p>\u25aa\ufe0f0xC000<\/p>\n<p>\u25aa\ufe0f0xC001<\/p>\n<p>\u25aa\ufe0f0xC002<\/td>\n<td style=\"width: 707px;height: 104px;text-align: left\">\n<ul style=\"text-align: start\">\n<li>Request information about data resources<\/li>\n<li>Request to receive information about its driver<\/li>\n<li>Execute SQL query<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 104px\">\n<td style=\"width: 109px;height: 104px;text-align: center\"><strong style=\"text-align: center\">Netstat<\/strong><\/td>\n<td style=\"width: 155px;height: 104px;text-align: center\">\n<p>\u25aa\ufe0f0xD000<\/p>\n<p>\u25aa\ufe0f0xD001<\/p>\n<p>\u25aa\ufe0f0xD002<\/td>\n<td style=\"width: 707px;height: 104px;text-align: left\">\n<ul>\n<li>Retrieve table of TCP connections<\/li>\n<li><span style=\"text-align: start\">Retrieve table of UDP connections<\/span><\/li>\n<li><span style=\"text-align: start\">Set a value in the TCP connection table.<\/span><\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr style=\"height: 96px\">\n<td style=\"width: 109px;height: 96px;text-align: center\"><strong style=\"text-align: center\">Keylogger<\/strong><\/td>\n<td style=\"width: 155px;height: 96px;text-align: center\">0xE000<\/td>\n<td style=\"width: 707px;height: 96px;text-align: left\">\n<ul>\n<li>Command to initiate the Keylogger thread<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2><\/h2>\n<h2><strong>How to deal with and clean the system?<\/strong><\/h2>\n<p>\u2714\ufe0f\u00a0Padvish antivirus detects and removes this particular malware from your system. To proactively safeguard your system against such threats, it is advisable to consider caution and avoid clicking on suspicious links. Additionally, routinely scan email attachments and portable devices before saving\/inserting them into your system.<\/p>\n<p>\u2714\ufe0f\u00a0Maintain the security of your system by consistently updating both your operating system and antivirus software to ensure the highest level of protection against evolving threats.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: HackTool Destruction Level: High Prevalence: Moderate Malware Name(s) Hacktool.Win32.BackdoorDiplomacy (Padvish ) Win32\/Korplug.A (Eset) Backdoor.Win32.Gulpix.ab (Kaspersky) Trojan:Win32\/Plugx.B (Microsoft ) What is HackTool? Hacktools are tools designed to facilitate intrusion. These tools can be used by an intruder to siphon data from the victim organization\u2019s network. These tools are commonly used to siphon the validation&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[47,48],"tags":[],"class_list":["post-1376","post","type-post","status-publish","format-standard","hentry","category-malware","category-hacktool"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1376","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1376"}],"version-history":[{"count":13,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1376\/revisions"}],"predecessor-version":[{"id":1546,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1376\/revisions\/1546"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1376"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1376"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1376"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}