{"id":1532,"date":"2024-04-16T08:07:02","date_gmt":"2024-04-16T08:07:02","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1532"},"modified":"2024-04-22T09:41:26","modified_gmt":"2024-04-22T09:41:26","slug":"hacktool-win32-nppspy","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/04\/16\/hacktool-win32-nppspy\/","title":{"rendered":"HackTool.Win32.NppSpy"},"content":{"rendered":"<h2 style=\"text-align: justify\">Overview<\/h2>\n<p style=\"text-align: justify\"><strong>Type:<\/strong> Hacktool<br \/>\n<strong>Destruction Level:<\/strong> High<br \/>\n<strong>Prevalence:<\/strong> Moderate<\/p>\n<p>&nbsp;<\/p>\n<h3>Malware Name(s)<\/h3>\n<ul>\n<li>(Padvish) HackTool.Win32.NppSpy<\/li>\n<li>(Avira) TR\/PSW.Agent.zmiws<\/li>\n<li>(Kaspersky)Trojan-PSW.Win32.Lognot.e<\/li>\n<\/ul>\n<h3><\/h3>\n<h3 style=\"text-align: justify\">What is HackTool?<\/h3>\n<p style=\"text-align: justify\">Hacktools are tools designed to facilitate intrusion. These tools can be used by an intruder to receive data from the victim organization\u2019s network. These tools are commonly used to retrieve credentials information of sensitive victim servers. For example, an intruder can use hacktools to guess passwords based on Brute Force attacks. In some cases, to escalate access levels and exploit existing vulnerabilities, HackTools are used. In general, hack tools can crash the computer and network security barriers and provide various capabilities to infiltrate systems.<\/p>\n<h3><\/h3>\n<h3 style=\"text-align: justify\">What is NppSpy Malware?<\/h3>\n<p style=\"text-align: justify\">NppSpy is an intrusion tool designed to steal user login credentials by masquerading its file as a Network Provider. Each Network Provider functions as a Windows Dynamic Link Library (DLL), facilitating the system&#8217;s compatibility with distinct network protocols. These files are automatically invoked by a system process upon user login or password modification, thereby transmitting related username and password data. Exploiting this mechanism, NppSpy malware registers its malicious file as a Network Provider. Consequently, it intercepts system notifications during login or password modification events, then it accesses sensitive user information, including usernames and passwords. This malware openly stores the obtained data in a file on the hard disk.<\/p>\n<p>&nbsp;<\/p>\n<h2>Technical Review<\/h2>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<p>? Detection of suspicious DLL files (the registered files as Network Providers are located in the following path:<\/p>\n<p><span style=\"color: #0000ff\">%SystemRoot%\\System32\\<\/span><\/p>\n<p>? Detection of suspicous file containing system user credentials, commonly found at:<\/p>\n<p><span style=\"color: #0000ff\">SystemRoot%\\temp\\msedge_installers.zip%<\/span><\/p>\n<p><span style=\"color: #0000ff\">SystemRoot%\\debug\\debug.evtx%<\/span><\/p>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify\">Performance Description<\/h3>\n<p style=\"text-align: justify\">The main file of this tool comprises a DLL file, which is meticulously registered as a Network Provider within the targeted system. To achieve this, the malware deploys a PowerShell script like the one depicted in image 1. This script registers the main malware file (designated as Ntkerbo.dll within the System32 directory) as a Network Provider and initiates the creation of the requisite service.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4045 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/04\/\u062a\u0635\u0648\u06cc\u0631-1-\u0627\u0633\u06a9\u0631\u06cc\u067e\u062a-\u067e\u0627\u0648\u0631\u0634\u0644-\u0628\u062f\u0627\u0641\u0632\u0627\u0631-\u0628\u0631\u0627\u06cc-\u062b\u0628\u062a-Network-Provider.png\" alt=\"\u0627\u0633\u06a9\u0631\u06cc\u067e\u062a \u067e\u0627\u0648\u0631\u0634\u0644 \u0628\u062f\u0627\u0641\u0632\u0627\u0631 \u0628\u0631\u0627\u06cc \u062b\u0628\u062a Network Provider\" width=\"1339\" height=\"223\" \/><\/p>\n<p style=\"text-align: center\">Image 1 &#8211; Malware Powershell script for registering Network Provider<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">When the user logs in the system, the Winlogon.exe process sends the username and password entered by the user to the mpnotify.exe process for authentication. This process also reads the Network Providers registered in the system from the following registry key and after loading the library file corresponding to them, it sends the login information openly to the NPLogonNotify function implemented in these files.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: left\"><span style=\"color: #0000ff\">\u201dHKLM\\SYSTEM\\CurrentControlSet\\Control\\NetworkProvider\\Order\\ProviderOrder\u201c<\/span><\/p>\n<p>Upon password alteration, the lsass.exe process loads and executes the registered Network Provider files.<\/p>\n<p>NppSpy saves stolen login credentials explicitly into a file on the victim&#8217;s disk, as illustrated below:<\/p>\n<p dir=\"ltr\" style=\"text-align: justify\"><span style=\"color: #0000ff\">\u201cUsername -&gt; password\\r\\n\u201d<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4047 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/04\/\u062a\u0635\u0648\u06cc\u0631-2\u2014-\u06a9\u062f-\u0630\u062e\u06cc\u0631\u0647-\u0633\u0627\u0632\u06cc-\u0627\u0637\u0644\u0627\u0639\u0627\u062a-\u06a9\u0627\u0631\u0628\u0631-\u062f\u0631-\u062a\u0627\u0628\u0639-NPLogonNotify.png\" alt=\"\u06a9\u062f \u0630\u062e\u06cc\u0631\u0647 \u0633\u0627\u0632\u06cc \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u06a9\u0627\u0631\u0628\u0631 \u062f\u0631 \u062a\u0627\u0628\u0639 NPLogonNotify\" width=\"764\" height=\"465\" \/><\/p>\n<p style=\"text-align: center\">Image 2 &#8211; Code snippet showcasing user data storage within the NPLogonNotify function<\/p>\n<p style=\"text-align: justify\">Image 3 illustrates the loading of the malware library file in the lsass.exe process, then its malicious activity, which involves logging the acquired information into a file on the hard disk:<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4056 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/04\/\u062a\u0635\u0648\u0631\u06cc\u0631-3.png\" alt=\"\u0627\u062c\u0631\u0627\u06cc \u0641\u0627\u06cc\u0644 \u0628\u062f\u0627\u0641\u0632\u0627\u0631 \u062f\u0631 \u0632\u0645\u0627\u0646 \u062a\u063a\u06cc\u06cc\u0631 \u0631\u0645\u0632 \u0639\u0628\u0648\u0631 \u062a\u0648\u0633\u0637 \u067e\u0631\u062f\u0627\u0632\u0647 lsass.exe\" width=\"873\" height=\"441\" \/><\/p>\n<p>Image 3 &#8211; Execution of the malware file during password modification by the lsass.exe process<\/p>\n<p>&nbsp;<\/p>\n<h2 style=\"text-align: justify\">How to deal with and clean the system<\/h2>\n<p>Padvish antivirus effectively detects and removes this malware from infected systems. To prevent infection, it is recommended to:<\/p>\n<p>\u2705Keep Your Antivirus Up to date<\/p>\n<p>\u2705Only download files or software from trusted sources and websites.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Hacktool Destruction Level: High Prevalence: Moderate &nbsp; Malware Name(s) (Padvish) HackTool.Win32.NppSpy (Avira) TR\/PSW.Agent.zmiws (Kaspersky)Trojan-PSW.Win32.Lognot.e What is HackTool? Hacktools are tools designed to facilitate intrusion. These tools can be used by an intruder to receive data from the victim organization\u2019s network. These tools are commonly used to retrieve credentials information of sensitive victim servers.&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[48],"tags":[56,67,68],"class_list":["post-1532","post","type-post","status-publish","format-standard","hentry","category-hacktool","tag-hacktool","tag-hacktool-win32-nppspy","tag-nppspy"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1532"}],"version-history":[{"count":3,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1532\/revisions"}],"predecessor-version":[{"id":1535,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1532\/revisions\/1535"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}