{"id":1577,"date":"2024-06-12T07:18:09","date_gmt":"2024-06-12T07:18:09","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1577"},"modified":"2024-06-18T07:45:06","modified_gmt":"2024-06-18T07:45:06","slug":"spy-win32-geremas","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/06\/12\/spy-win32-geremas\/","title":{"rendered":"Spy.Win32.Geremas"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Spyware<br \/>\n<strong>Destruction Level:<\/strong> High<br \/>\n<strong>Prevalence:<\/strong> Low<\/p>\n<h3>\n<strong>Malware Names<\/strong><\/h3>\n<p>\u2022 (Padvish) Spy.Win32.Geremas<br \/>\n\u2022 (Avira) TR\/Spy.Gen<br \/>\n\u2022 (Kaspersky) HEUR:Trojan-PSW.MSIL.Geremas.gen<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What is Spyware?<\/strong><\/h3>\n<p style=\"text-align: justify\">Spyware is a type of malware used for spying and stealing personal and organizational information. Once installed on a user&#8217;s device, spyware continuously threatens data security, potentially stealing and transmitting information to unauthorized parties. Typically, spyware is installed covertly and operates without the user&#8217;s knowledge, often masquerading as a legitimate application. This type of malware collects data on user activities, such as passwords, credit card details, keystrokes, call logs, contact lists, and text messages, then sends to external entities.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>What is the Geremas malware?<\/strong><\/h3>\n<p>Geremas is a type of spyware designed to steal information from victims and send it to an email address. Targeted data includes information stored in the Chrome browser, system passwords, and details from the Telegram application.<\/p>\n<p>&nbsp;<\/p>\n<h2>\nTechnical Description<\/h2>\n<h3>Indicators of Compromise<\/h3>\n<p>\u274c\u00a0Presence of a file with the <span style=\"color: #0000ff\">.bat<\/span> extension, as well as <span style=\"color: #0000ff\">SAMS<\/span> and <span style=\"color: #0000ff\">SYSTEM<\/span> files in the<strong> C:\\ path<\/strong><br \/>\n\u274c\u00a0Presence of a file named <span style=\"color: #0000ff\">protects.zip<\/span> in the <strong>%AppData%<\/strong> path<\/p>\n<p style=\"text-align: justify\">\nPerformance Description:<br \/>\nData Theft:<br \/>\nWhen executed, this malware creates a file named ree.bat in the C:\\File\\ree.bat path and runs it at regular intervals to steal stored passwords. It stores information in the <span style=\"color: #0000ff\">HKLM\/SAM<\/span> and <span style=\"color: #0000ff\">HKLM\/SYSTEM<\/span> registry keys, where the SAM key encrypts system passwords and the SYSTEM key contains decryption information.<br \/>\nThe ree.bat file code is shown in the image below:<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4170 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/06\/\u06a9\u062f-\u0641\u0627\u06cc\u0644-ree.bat-1.png\" alt=\"\u06a9\u062f \u0641\u0627\u06cc\u0644 ree.bat\" width=\"651\" height=\"266\" \/><\/p>\n<p style=\"text-align: center\">\nree.bat file code<\/p>\n<p>&nbsp;<\/p>\n<p>Additional data collected by this malware includes:<br \/>\n\u2022 System user passwords, saved in the <em>%AppData%\/protects.zip<\/em> file and sent to a malicious server<br \/>\n\u2022 Login information and cookies from <em>Google Chrome<\/em>, extracted from:<br \/>\n<span style=\"color: #0000ff\">\u00a0%AppData%\/Local\/Google\/Chrome\/User Data\/Default\/Network\/Cookies<\/span><br \/>\n<span style=\"color: #0000ff\">\u00a0%AppData%\/Local\/Google\/Chrome\/User Data\/Default\/Network\/Login Data<\/span><br \/>\n<span style=\"color: #0000ff\">\u00a0%AppData%\/Local\/Google\/Chrome\/User Data\/Default\/Network\/Local State<\/span><br \/>\n\u2022 <em>Telegram Desktop<\/em> information, collected from:<br \/>\n<span style=\"color: #0000ff\">%AppData%\/Telegram Desktop\/tdata\/key_datas<\/span><br \/>\n<span style=\"color: #0000ff\">%AppData%\/Telegram Desktop\/tdata\/D877F783D5D3EF8C<\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Sending Information to the Server<\/strong><br \/>\nTo transmit stolen data, the malware logs into a gmail.com account with the following credentials and sends the information as an email attachment:<br \/>\n\u2022 Username: <em>alqasabiibrahim2@gmail.com<\/em><br \/>\n\u2022 Password: <em>yknglwcjirbnbirb<\/em><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4171 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/06\/2-\u0627\u0631\u0633\u0627\u0644-\u0627\u06cc\u0645\u06cc\u0644-\u062d\u0627\u0648\u06cc-\u0627\u0637\u0644\u0627\u0639\u0627\u062a-\u0633\u0631\u0642\u062a-\u0634\u062f\u0647.png\" alt=\"\u0627\u0631\u0633\u0627\u0644 \u0627\u06cc\u0645\u06cc\u0644 \u062d\u0627\u0648\u06cc \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0633\u0631\u0642\u062a \u0634\u062f\u0647\" width=\"1199\" height=\"619\" \/><\/p>\n<p style=\"text-align: center\">Sending emails containing stolen data<\/p>\n<p>To ensure persistence, the malware copies itself to the Windows <em>startup<\/em> path, ensuring it runs automatically at every system startup:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4172 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/06\/3-\u06a9\u067e\u06cc-\u06a9\u0631\u062f\u0646-\u0641\u0627\u06cc\u0644-\u0627\u0635\u0644\u06cc-\u062f\u0631-\u0645\u0633\u06cc\u0631-startup.png\" alt=\"\u06a9\u067e\u06cc \u06a9\u0631\u062f\u0646 \u0641\u0627\u06cc\u0644 \u0627\u0635\u0644\u06cc \u062f\u0631 \u0645\u0633\u06cc\u0631 startup\" width=\"1212\" height=\"172\" \/><\/p>\n<p style=\"text-align: center\">Copying the original file to the <em>startup<\/em> path<\/p>\n<p>&nbsp;<\/p>\n<h2>How to Deal with and Clean the System<\/h2>\n<p><a href=\"http:\/\/padvish.com\"><span style=\"color: #0000ff\">Padvish<\/span> <\/a>Antivirus can detect and remove this malware. To prevent infection:<br \/>\n\u2022 Keep your antivirus software up to date.<br \/>\n\u2022 Download files from reliable sources.<br \/>\n\u2022 Avoid clicking on suspicious links and scan email attachments with antivirus software.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Spyware Destruction Level: High Prevalence: Low Malware Names \u2022 (Padvish) Spy.Win32.Geremas \u2022 (Avira) TR\/Spy.Gen \u2022 (Kaspersky) HEUR:Trojan-PSW.MSIL.Geremas.gen &nbsp; What is Spyware? Spyware is a type of malware used for spying and stealing personal and organizational information. Once installed on a user&#8217;s device, spyware continuously threatens data security, potentially stealing and transmitting information to&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[77,78],"class_list":["post-1577","post","type-post","status-publish","format-standard","hentry","category-spyware","tag-spy","tag-geremas"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1577"}],"version-history":[{"count":1,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1577\/revisions"}],"predecessor-version":[{"id":1578,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1577\/revisions\/1578"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}