{"id":1567,"date":"2024-05-21T09:16:09","date_gmt":"2024-05-21T09:16:09","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1567"},"modified":"2024-05-26T10:02:08","modified_gmt":"2024-05-26T10:02:08","slug":"trojan-win32-mornhya","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/05\/21\/trojan-win32-mornhya\/","title":{"rendered":"Trojan.Win32.Mornhya"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Trojan<br \/>\n<strong>Destruction Level:<\/strong> Moderate<br \/>\n<strong>Prevalence:<\/strong> Moderate<\/p>\n<p>&nbsp;<\/p>\n<h3>Malware Names<\/h3>\n<ul>\n<li>Trojan.Win32.Mornhya (Padvish)<\/li>\n<li>Powershell\/Kriptik(Eset)<\/li>\n<li>Trojan.Bat.Alien(Microsoft)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify\">What is Trojan?<\/h3>\n<p style=\"text-align: justify\">Trojan is a type of malware that disguises itself as clean and legitimate software and behaves totally like a useful and functional software, but when executed, it causes a lot of damage to the computer system. There are different ways in which trojans could enter the system, some are: Entering through a software downloaded from the Internet, embedding in HTML text, attaching to an email, etc.<\/p>\n<p>&nbsp;<\/p>\n<h3>What is Mornhya malware?<\/h3>\n<p style=\"text-align: justify\">Mornhya is a obscured <em>batch<\/em> file (typically with a .cmd extension) that, upon execution and after disambiguation, executes a miner file. The malware employs various techniques to evade detection and monitoring by security tools. In observed cases, samples of this malware have been downloaded from the following addresses, often disguised as software cracks:<\/p>\n<p style=\"text-align: left\"><em><span style=\"color: #0000ff\">hxxp[:]\/\/89[.]23[.]97[.]199[:]1444<\/span><\/em><\/p>\n<p style=\"text-align: left\"><em><span style=\"color: #0000ff\">hxxps[:]\/\/89[.]23[.]97[.]199<\/span><\/em><\/p>\n<p>&nbsp;<\/p>\n<h2>Technical Review<\/h2>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/11\/svg\/1f53a.svg\" alt=\"?\" width=\"13\" height=\"13\" \/>Presence of a .<em>cmd<\/em> file in the `%programdata%\\Microsoft%` path, with names seen in different malware samples such as:<\/p>\n<p><em>WinDriver.cmd<\/em><br \/>\n<em>Anonmy.cmd<\/em><br \/>\n<em>Project88.cmd<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/11\/svg\/1f53a.svg\" alt=\"?\" width=\"13\" height=\"13\" \/>High CPU usage by the `<span style=\"color: #0000ff\">explorer.exe<\/span>` process or `<span style=\"color: #0000ff\">xmrig.exe<\/span>` program process.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/11\/svg\/1f53a.svg\" alt=\"?\" width=\"13\" height=\"13\" \/>System processes internet connection to the following mining domain (e.g., `<span style=\"color: #0000ff\">powershell.exe<\/span>`, `<span style=\"color: #0000ff\">explorer.exe<\/span>`, <span style=\"color: #000000\">or<\/span> `<span style=\"color: #0000ff\">xmrig.exe<\/span>`)<br \/>\n<em><span style=\"color: #0000ff\">pool[.]hashvault[.]pro<\/span><\/em><\/p>\n<p>&nbsp;<\/p>\n<h3>Performance Description<\/h3>\n<p style=\"text-align: justify\"><em>Mornhya<\/em> malware is a <em>batch<\/em> file that ultimately executes a miner on the victim&#8217;s system. This file is obfuscated and disambiguated in several stages. Initially, the malware runs a command-line command, creates a subprocess `<em>powershell.exe<\/em>` to execute an obscured code fragment:<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4127\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/\u062a\u0635\u0648\u06cc\u0631-1.png\" alt=\"\u0634\u0631\u062d \u0639\u0645\u0644\u06a9\u0631\u062f \u0628\u062f\u0627\u0641\u0632\u0627\u0631 Mornhya\" width=\"1222\" height=\"180\" \/><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">After disambiguation, the PowerShell code snippet is as follows. The malware first reads the pseudocode in the original file, decrypts it using the <em>AES<\/em> algorithm, and then decompresses it from <em>GZip<\/em>. By executing this code, two malicious <em>PE<\/em> files are obtained and loaded directly into the `<em>powershell.exe<\/em>` memory process.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4129\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/\u062a\u0635\u0648\u06cc\u0631-2.png\" alt=\"\u0634\u0631\u062d \u0639\u0645\u0644\u06a9\u0631\u062f \u0628\u062f\u0627\u0641\u0632\u0627\u0631 Mornhya\" width=\"1262\" height=\"587\" \/><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The first file (referred to as <em>AMSIPatcher<\/em>) employs various techniques to bypass antivirus and other security tools. Once the first file is executed, the second file is loaded and executed within the `<em>powershell.exe<\/em>` memory to run the `<em>xmrig.exe<\/em>` miner.<\/p>\n<p>&nbsp;<\/p>\n<p>?<strong>The First File: <em>AMSIPatcher<\/em><\/strong><\/p>\n<p style=\"text-align: justify\"><em>Mornhya<\/em> malware, in<em> AMSIPatcher.exe<\/em> file, uses the following techniques to bypass antivirus and monitoring tools. The following figure presents a code sample of <em>AMSIPatcher<\/em>:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4130\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/3-\u06a9\u062f-\u0646\u0645\u0648\u0646\u0647\u200c\u0627\u06cc-\u0627\u0632-\u0641\u0627\u06cc\u0644-AMSIPatcher.png\" alt=\"\u06a9\u062f \u0646\u0645\u0648\u0646\u0647\u200c\u0627\u06cc \u0627\u0632 \u0641\u0627\u06cc\u0644 AMSIPatcher\" width=\"1261\" height=\"198\" \/><\/p>\n<ul>\n<li style=\"text-align: justify\"><strong>Upload clean Versions of <em>kernel32.dll<\/em> and <em>ntdll.dll<\/em> Files:\u00a0<\/strong>The malware locates `ntdll.dll` and `kernel32.dll` modules among the uploaded modules of the `powershell.exe` process. It also loads clean versions of these files into the malware process memory, then it changes the start address of the code in these modules to the start address of the clean versions it has uploaded. This allows the malware to bypass hooks that may have been applied to the functions of these two modules during the creation of the `powershell.exe` process.<\/li>\n<li style=\"text-align: justify\"><strong><em>AMSIScanBuffer<\/em> Function Code Modification:\u00a0<\/strong>The AMSIScanBuffer function from the `amsi.dll` library, is used to scan buffer contents in the memory. The malware modifies the initial bytes of this function to prevent its execution, so the function returns without running the original code. For example, in 64-bit Windows, the malware rewrites the initial bytes with [184, 87, 0, 7, 128, 194, 24, 0] bites, whose assembly equivalent command is shown below.&#8221;<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-4131 size-full\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/\u062a\u0635\u0648\u06cc\u0631-4.png\" alt=\"\u2022 \u062a\u063a\u06cc\u06cc\u0631 \u06a9\u062f \u062a\u0627\u0628\u0639 AMSIScanBuffer \" width=\"1371\" height=\"75\" \/><\/p>\n<ul>\n<li style=\"text-align: justify\"><strong><em>EtwEventWrite<\/em> Function Code change:\u00a0<\/strong>To avoid logging its own process events, the malware changes the initial bytes of this function in the `ntdll.dll` module to [194, 20, 0] in 32-bit Windows and [195] in 64-bit Windows. This is equivalent to the &#8220;&#8221;ret&#8221;&#8221; command in assembly language, making the function return immediately without executing its code<\/li>\n<\/ul>\n<p><strong>?The Second File: <em>Miner<\/em><\/strong><\/p>\n<p style=\"text-align: justify\">The miner file varies in different malware samples , but ultimately executes the `xmrig.exe` mining tool on the victim&#8217;s system, typically using the following address as a mining pool:<\/p>\n<p><span style=\"color: #0000ff\"><em>pool[.]hashvault[.]pro<\/em><\/span><\/p>\n<p style=\"text-align: justify\">For instance, in one malware sample, the malware miner file is based on the <em>.NET<\/em> framework and contains two malicious resources similar to the following figure. The first resource, <em>LP<\/em> resource in the following figure, is a malicious library file named `<em>LoadPE.dll<\/em>` that executes the second resource, P. Resource P is a malware that, upon execution, creates a subprocess with a clean Windows file `<em>explorer.exe<\/em>`, and injects the `xmrig.exe` miner file into it.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-4132 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/5-\u0641\u0627\u06cc\u0644-\u062f\u0648\u0645-Miner.png\" alt=\" \u0641\u0627\u06cc\u0644 \u062f\u0648\u0645- Miner\" width=\"1356\" height=\"259\" \/><\/p>\n<p>The following figure illustrates the malware execution:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4146\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/05\/5-\u0627\u062c\u0631\u0627\u06cc-\u0628\u062f\u0627\u0641\u0632\u0627\u0631-Mornhya-1.png\" alt=\"\u0627\u062c\u0631\u0627\u06cc \u0628\u062f\u0627\u0641\u0632\u0627\u0631 Mornhya\" width=\"1213\" height=\"243\" \/><\/p>\n<p>&nbsp;<\/p>\n<h2>How to deal with and clean the system?<\/h2>\n<p>Padvish Antivirus detects and removes this malware from the system. It is recommended to:<\/p>\n<p>\u2705 Always keep your OS and antivirus up to date.<br \/>\n\u2705 Download files only from reliable sources.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan Destruction Level: Moderate Prevalence: Moderate &nbsp; Malware Names Trojan.Win32.Mornhya (Padvish) Powershell\/Kriptik(Eset) Trojan.Bat.Alien(Microsoft) &nbsp; What is Trojan? Trojan is a type of malware that disguises itself as clean and legitimate software and behaves totally like a useful and functional software, but when executed, it causes a lot of damage to the computer system.&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[43,76],"class_list":["post-1567","post","type-post","status-publish","format-standard","hentry","category-trojan","tag-trojan","tag-mornhya"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1567","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1567"}],"version-history":[{"count":7,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1567\/revisions"}],"predecessor-version":[{"id":1575,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1567\/revisions\/1575"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}