{"id":1425,"date":"2024-02-14T08:13:35","date_gmt":"2024-02-14T08:13:35","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1425"},"modified":"2024-04-22T12:49:06","modified_gmt":"2024-04-22T12:49:06","slug":"backdoor-win32-jackalcontrol","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/02\/14\/backdoor-win32-jackalcontrol\/","title":{"rendered":"Backdoor.Win32.JackalControl"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Trojan<br \/>\n<strong>Destruction Level:<\/strong> High<br \/>\n<strong>Prevalence:<\/strong> Moderate<\/p>\n<p>&nbsp;<\/p>\n<h3>Malware Name(s)<\/h3>\n<ul>\n<li>Backdoor.Win32.JackalControl.ap (Padvish)<\/li>\n<li>HEUR:Trojan.MSIL.Agent.gen (Kaspersky)<\/li>\n<li>A Variant Of MSIL\/Small.DF (Eset)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3>What is Backdoor Malware?<\/h3>\n<p>Backdoors are applications designed to allow hackers to bypass the system security mechanism, granting unauthorized access to various system resources. Hackers can enter the system, with no concern for altered usernames or passwords, bypass authentication protocols. These applications come in various forms and hackers use them upon their needs to breach a system resource.<\/p>\n<p>&nbsp;<\/p>\n<h3>What is JackalControl Malware?<\/h3>\n<p>Golden Jackal is the name of a hacker group renowned for creating multiple malwares in the .NET language, leveraging them to target select organizations across the Middle East and South Asia.. The scope of their target is inferred based on the content inside an infected Microsoft Office Word file (as one of the methods of spreading this malware family). This group has developed five malware named JackalControl, JackalSteal, JackalScreenWatcher, JackalPerInfo and JackalWorm. The following report describes the performance of the JackalControl malware from this family.<\/p>\n<p>&nbsp;<\/p>\n<h2>Technical Review<\/h2>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<p>Upon receiving arguments, the system may exhibit one of the following signs:<\/p>\n<p>1. Creation of an in-system task to execute a copy of the malware in either the %ALLUSERSPROFILE% or %Temp% paths.<br \/>\n2. Establishment of a registry key in the path HKEY_Current_User\\Software\\Microsoft\\Windows\\CurrentVersion\\Run.<br \/>\n3. Generation of a service using the sc.exe tool within the Windows OS.<\/p>\n<p>&nbsp;<\/p>\n<h3>Performance Description<\/h3>\n<p>Depending on the arguments provided from the command line, the malware executes one of the following operations on the system:<br \/>\n\/h0: Creates a task to execute the malware&#8217;s survival file.<br \/>\n\/h1: Creates a value to the RUN registry key to execute the malware&#8217;s survival file.<br \/>\n\/h2: Creates a service to execute the malware.<br \/>\n\/r0: Executes as a standard process via a scheduled task.<br \/>\n\/r1: Executes as a standard process via the RUN registry key.<br \/>\n\/r2: Executes as a service.<\/p>\n<p>&nbsp;<\/p>\n<h4>The malware then extracts the following three values from the system to create an ID:<\/h4>\n<ul>\n<li>UUID<\/li>\n<li>Machine GUID<\/li>\n<li>Serial Number for PHYSICALDRIVE0<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3899 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/1-\u0627\u0633\u062a\u062e\u0631\u0627\u062c-\u0645\u0642\u062f\u0627\u0631-UUID-\u0631\u0627-\u062c\u0647\u062a-\u0627\u06cc\u062c\u0627\u062f-\u06cc\u06a9-\u0634\u0646\u0627\u0633\u0647-ID-\u0627\u0632-\u062f\u0631\u0648\u0646-\u0633\u06cc\u0633\u062a\u0645.png\" alt=\"\u0627\u0633\u062a\u062e\u0631\u0627\u062c \u0645\u0642\u062f\u0627\u0631 UUID \u0631\u0627 \u062c\u0647\u062a \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0634\u0646\u0627\u0633\u0647 (ID) \u0627\u0632 \u062f\u0631\u0648\u0646 \u0633\u06cc\u0633\u062a\u0645\" width=\"1062\" height=\"128\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3900 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/2-\u0627\u0633\u062a\u062e\u0631\u0627\u062c-\u0645\u0642\u062f\u0627\u0631-Machine-GUID-\u0631\u0627-\u062c\u0647\u062a-\u0627\u06cc\u062c\u0627\u062f-\u06cc\u06a9-\u0634\u0646\u0627\u0633\u0647-ID-\u0627\u0632-\u062f\u0631\u0648\u0646-\u0633\u06cc\u0633\u062a\u0645.png\" alt=\"\u0627\u0633\u062a\u062e\u0631\u0627\u062c \u0645\u0642\u062f\u0627\u0631 Machine GUID \u0631\u0627 \u062c\u0647\u062a \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0634\u0646\u0627\u0633\u0647 (ID) \u0627\u0632 \u062f\u0631\u0648\u0646 \u0633\u06cc\u0633\u062a\u0645\" width=\"1053\" height=\"141\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3901 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/3-\u0627\u0633\u062a\u062e\u0631\u0627\u062c-\u0645\u0642\u062f\u0627\u0631-Machine-GUID-\u0631\u0627-\u062c\u0647\u062a-\u0627\u06cc\u062c\u0627\u062f-\u06cc\u06a9-\u0634\u0646\u0627\u0633\u0647-ID-\u0627\u0632-\u062f\u0631\u0648\u0646-\u0633\u06cc\u0633\u062a\u0645.png\" alt=\"\u0627\u0633\u062a\u062e\u0631\u0627\u062c \u0645\u0642\u062f\u0627\u0631 Machine GUID \u0631\u0627 \u062c\u0647\u062a \u0627\u06cc\u062c\u0627\u062f \u06cc\u06a9 \u0634\u0646\u0627\u0633\u0647 (ID) \u0627\u0632 \u062f\u0631\u0648\u0646 \u0633\u06cc\u0633\u062a\u0645\" width=\"1064\" height=\"138\" \/><\/p>\n<p>An identifier is generated using the parameters provided and through the algorithm depicted in the image below. This identifier will then be utilized in the encryption algorithm.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3902 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/4-\u0627\u06cc\u0646-\u0627\u0644\u06af\u0648\u0631\u06cc\u062a\u0645-\u0631\u0645\u0632\u06af\u0630\u0627\u0631\u06cc-\u06a9\u0647-DES-\u062f\u0631-\u062d\u0627\u0644\u062a-CBC.png\" alt=\"\u0627\u06cc\u0646 \u0627\u0644\u06af\u0648\u0631\u06cc\u062a\u0645 \u0631\u0645\u0632\u06af\u0630\u0627\u0631\u06cc \u06a9\u0647 DES \u062f\u0631 \u062d\u0627\u0644\u062a CBC\" width=\"909\" height=\"270\" \/><\/p>\n<h4><\/h4>\n<p>The encryption algorithm used for one of the data encryption steps before sending it to the malware server is DES in CBC mode.<\/p>\n<p>If the malware is executed without input arguments in the system, the ID creation procedure is reiterated. After sending the data to the server, the malware&#8217;s survival process in the system proceeds as follows:<\/p>\n<p>1\ufe0f\u20e3 The malware extracts the folders within the %ALLUSERSPROFILE% path on the current system and selects a random folder from the list to place a copy of itself inside. The naming pattern for the malware survival file follows this pattern:<\/p>\n<p>Launcher.exe + a randomly chosen folder name from the path + %ALLUSERSPROFILE%<\/p>\n<p>For instance: MicrosoftLauncher.exe<\/p>\n<p>In previous versions of the malware, the fixed character string Update.exe was used instead of Launcher.exe in the mentioned naming pattern.<\/p>\n<p>2\ufe0f\u20e3 If the copying process described above fails, the malware proceeds to search the following folders and attempts to copy itself into one of them:<\/p>\n<ul>\n<li><span style=\"color: #0000ff\"><em>Google<\/em><\/span><\/li>\n<li><span style=\"color: #0000ff\"><em>Viber<\/em><\/span><\/li>\n<li><span style=\"color: #0000ff\"><em>AdGuard<\/em><\/span><\/li>\n<li><span style=\"color: #0000ff\"><em>WinZip<\/em><\/span><\/li>\n<li><span style=\"color: #0000ff\"><em>WinRAR<\/em><\/span><\/li>\n<li><span style=\"color: #0000ff\"><em>Adobe<\/em><\/span><\/li>\n<li><span style=\"color: #0000ff\"><em>CyberLink<\/em><\/span><\/li>\n<li><span style=\"color: #0000ff\"><em>Intel<\/em><\/span><\/li>\n<\/ul>\n<p>3\ufe0f\u20e3 If the above-mentioned procedure also fails, the malware will be copied into one of the following paths:<\/p>\n<ul>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>%ALLUSERSPROFILE%<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>%LOCALAPPDATA%<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>%Temp%<\/em><\/span><\/li>\n<\/ul>\n<p>4\ufe0f\u20e3 After the copying process is completed, a task will be periodically created to execute the malware survival file. This task file will be generated alongside the malware survival file. Once the task is successfully created, the initial file will be deleted.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3903 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/6-\u0627\u06cc\u062c\u0627\u062f-Task-\u062c\u0647\u062a-\u0627\u062c\u0631\u0627\u06cc-\u0641\u0627\u06cc\u0644-\u0628\u0642\u0627\u06cc-\u0628\u062f\u0627\u0641\u0632\u0627\u0631-\u0628\u0647-\u0635\u0648\u0631\u062a-\u062f\u0648\u0631\u0647\u200c\u0627\u06cc.png\" alt=\"\u0627\u06cc\u062c\u0627\u062f Task \u062c\u0647\u062a \u0627\u062c\u0631\u0627\u06cc \u0641\u0627\u06cc\u0644 \u0628\u0642\u0627\u06cc \u0628\u062f\u0627\u0641\u0632\u0627\u0631 \u0628\u0647 \u0635\u0648\u0631\u062a \u062f\u0648\u0631\u0647\u200c\u0627\u06cc\" width=\"883\" height=\"209\" \/><\/p>\n<h4><\/h4>\n<p><strong>How the malware communicates with it&#8217;s C&amp;C?<\/strong><\/p>\n<p>Before establishing the initial connection to its command and control (C&amp;C) server, the malware gathers the victim&#8217;s system ID along with the following information:<\/p>\n<ul>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>Computer name<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>OS version<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>Domain<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>User<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>Local time<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>Interfaces(DESC, TYPE, MAC, IP, GW, DNS, DHCP, DOMAIN)<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>Remote IP<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>Current directory<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>Drives<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>Applications<\/em><\/span><\/li>\n<li style=\"text-align: left\"><span style=\"color: #0000ff\"><em>Processes<\/em><\/span><\/li>\n<\/ul>\n<p>All information is then encrypted and sent to the malware server in the following format:<\/p>\n<p style=\"text-align: left\"><span style=\"color: #0000ff\"><strong><em>base64 + base64 + DES + GZip<\/em><\/strong><\/span><\/p>\n<p>The final example of the package sent to the malware server is as follows:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3904\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/\u0646\u0645\u0648\u0646\u0647-\u0646\u0647\u0627\u06cc\u06cc-\u0628\u0633\u062a\u0647\u200c\u06cc-\u0627\u0631\u0633\u0627\u0644\u06cc-\u0628\u0647-\u0633\u0631\u0648\u0631-\u0628\u062f\u0627\u0641\u0632\u0627\u0631-7.png\" alt=\"\u0646\u0645\u0648\u0646\u0647 \u0646\u0647\u0627\u06cc\u06cc \u0628\u0633\u062a\u0647\u200c\u06cc \u0627\u0631\u0633\u0627\u0644\u06cc \u0628\u0647 \u0633\u0631\u0648\u0631 \u0628\u062f\u0627\u0641\u0632\u0627\u0631 \" width=\"872\" height=\"368\" \/><\/p>\n<p>Communication with the server is conducted via HTTPS. The following are two examples of communication addresses utilized by this version of the malware:<\/p>\n<p style=\"text-align: left\"><span style=\"color: #0000ff\"><em>hxxps:\/\/nassiraq.iq\/wp-includes\/class-wp-header-styles.php\u00a0\u00a0?<\/em><\/span><\/p>\n<p style=\"text-align: left\"><span style=\"color: #0000ff\"><em>hxxps:\/\/sokerpower.com\/wp-includes\/class-wp-header-styles.php\u00a0?<\/em><\/span><\/p>\n<p>Upon establishing communication with the attacker&#8217;s server, the malware gains the capability to execute programs, download files onto the victim&#8217;s system, and upload files from it.<\/p>\n<table style=\"border-collapse: collapse;width: 61.0986%;height: 96px\" border=\"1\">\n<tbody>\n<tr style=\"height: 24px\">\n<td style=\"width: 50%;text-align: center;height: 24px\">\u00a0Command Codes<\/td>\n<td style=\"width: 50%;text-align: center;height: 24px\">Function<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 50%;text-align: center;height: 24px\">00<\/td>\n<td style=\"width: 50%;height: 24px;text-align: center\">Execute the attacker&#8217;s desired program on the victim&#8217;s system.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 50%;text-align: center;height: 24px\">01<\/td>\n<td style=\"width: 50%;height: 24px;text-align: center\">Download file<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 50%;text-align: center;height: 24px\">02<\/td>\n<td style=\"width: 50%;height: 24px;text-align: center\">Upload file<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>In this report, one version of the Golden Jackal malware family is discussed. However, as previously mentioned, the Golden Jackal hacker group possesses various types of malware with distinct objectives. Consequently, attackers can deploy a combination of these malware variants to achieve their goals effectively.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>How to deal with and clean the system?<\/strong><\/h2>\n<p>Padvish antivirus detects and blocks the network communications used by Golden Jackal malware. Additionally, it detects various versions of this malware and effectively removes them from the system.<\/p>\n<p>\u2705 To prevent the risk of potential infection by this malware, refrain from opening emails from unknown sources and ensure regular updates of your OS.<\/p>\n<p>It is recommended to download software exclusively from reliable websites and trusted sources.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan Destruction Level: High Prevalence: Moderate &nbsp; Malware Name(s) Backdoor.Win32.JackalControl.ap (Padvish) HEUR:Trojan.MSIL.Agent.gen (Kaspersky) A Variant Of MSIL\/Small.DF (Eset) &nbsp; What is Backdoor Malware? Backdoors are applications designed to allow hackers to bypass the system security mechanism, granting unauthorized access to various system resources. Hackers can enter the system, with no concern for altered&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,47],"tags":[43,44,52,53],"class_list":["post-1425","post","type-post","status-publish","format-standard","hentry","category-trojan","category-malware","tag-trojan","tag-malware","tag-golden-jackal","tag-backdoor"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1425","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1425"}],"version-history":[{"count":13,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1425\/revisions"}],"predecessor-version":[{"id":1543,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1425\/revisions\/1543"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1425"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1425"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1425"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}