{"id":1579,"date":"2024-06-05T07:45:38","date_gmt":"2024-06-05T07:45:38","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1579"},"modified":"2024-06-18T09:12:13","modified_gmt":"2024-06-18T09:12:13","slug":"bot-win32-torzhok","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/06\/05\/bot-win32-torzhok\/","title":{"rendered":"Bot.Win32.Torzhok"},"content":{"rendered":"<h2>Overview<\/h2>\n<p>Type: Trojan<br \/>\nDestruction Level: High<br \/>\nPrevalence: Low<\/p>\n<p>&nbsp;<\/p>\n<h3>Malware names<\/h3>\n<p>Bot.Win32.Torzhok (Padvish)<br \/>\nGen:Variant.Adware.Symmi.87092 (bitdefender)<\/p>\n<p>&nbsp;<\/p>\n<p><strong>What is Trojan?<\/strong><br \/>\nTrojan is a type of malware that disguises itself as clean and legitimate software and behaves totally like a useful and functional software, but when executed, it causes a lot of damage to the computer system. There are different ways in which trojans could enter the system, some are: Entering through a software downloaded from the Internet, embedding in <em>HTML<\/em> text, attaching to an email, etc.<\/p>\n<p><strong>What is the Bot.Win32.Torzhok Malware?<\/strong><br \/>\nThe <em>Bot.Win32.Torzhok<\/em> malware operates with commands supported by a malicious bot. Notable actions of this malware include:<\/p>\n<p>\u2022 Uploading the victim&#8217;s files to the malware&#8217;s server<br \/>\n\u2022 Deleting and renaming files<br \/>\n\u2022 Downloading and executing files on the victim&#8217;s system<br \/>\n\u2022 Creating a terminal on the victim&#8217;s system to execute command-line commands issued by the server<\/p>\n<p>The malware server is a public service that makes the victim&#8217;s uploaded files accessible to intruders and allows its website audience to communicate with the infected systems and send them command-line commands.<\/p>\n<p>&nbsp;<\/p>\n<h2>\nTechnical Review<\/h2>\n<h3>Indicators of Compromise (IoCs)<\/h3>\n<p>\u274c Presence of a file named <span style=\"color: #0000ff\">.gu1d<\/span> in the path <span style=\"color: #0000ff\">%Temp%<\/span><br \/>\n\u274c Network connections with this the address: <span style=\"color: #0000ff\">hxxps:\/\/185[.]239[.]71[.]105<\/span><\/p>\n<h3>\nPerformance Description<\/h3>\n<p>Upon execution, the malware creates a GUID by invoking the Windows API <span style=\"color: #0000ff\">CoCreateGuid<\/span> and saves it in a file named .gu1d in the %Temp% directory. This data is used as a cookie in the malware&#8217;s communications with a remote server.<\/p>\n<p>Malware Server Address: <span style=\"color: #0000ff\">hxxps:\/\/185[.]239[.]71[.]105<\/span><br \/>\nThe malware then communicates with its command and control server over port 443 in the observed sample. It uses REST API functions to execute its operations.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<table style=\"border-collapse: collapse;width: 67.4467%;height: 217px\" border=\"1\">\n<tbody>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><strong>Function<\/strong><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: center\"><strong>Aim<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>api\/v1\/greeting\/<\/em><\/strong><\/span><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: right\">Introducing the victim&#8217;s system to the server by sending initial contact information.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>api\/v1\/register\/<\/em><\/strong><\/span><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: right\">Sending the victim&#8217;s system specifications to the server, including the full operating system details, system username, computer name, etc.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>api\/v1\/heartbeat\/<\/em><\/strong><\/span><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: right\">Receiving an identifier from the server corresponding to the victim&#8217;s host (the malware uses this identifier to receive tasks from the server).<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>api\/v1\/psnapshot\/<\/em><\/strong><\/span><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: right\">Sending a list of the victim&#8217;s system processes to the server.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>api\/v1\/todo\/<\/em><\/strong><\/span><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: right\">Retrieving new tasks from the server<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>api\/v1\/task\/<\/em><\/strong><\/span><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: right\">Notifying about the status of the incoming task.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>api\/v1\/fetch\/<\/em><\/strong><\/span><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: right\">Downloading files from the malware server.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>api\/v1\/explorer\/<\/em><\/strong><\/span><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: right\">Sending a list of the contents of a specific directory to the server.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>api\/v1\/mq\/<\/em><\/strong><\/span><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: right\">Receiving and executing command-line commands from the server on the victim&#8217;s system. A terminal is created on the victim&#8217;s system for this purpose, executing the received commands and sending the results back through the established pipe between the server and the infected system.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>api\/v1\/files\/<\/em><\/strong><\/span><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: right\">Uploading the contents of one or more files to the malware server.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 27.2449%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><strong><em>api\/v1\/goodbye\/<\/em><\/strong><\/span><\/td>\n<td style=\"width: 93.6671%;height: 24px;text-align: right\">Terminating the connection with the server.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center\">Table 1- Functions used by the malware to communicate with the server<\/p>\n<p>According to the descriptions mentioned in the table above, the malware requests a task from the server after introducing its system to the server and receiving the corresponding ID associated with its host. The task received from the server can include one of the following commands (payload value):<\/p>\n<p style=\"text-align: justify\">\n<table style=\"border-collapse: collapse;width: 69.7962%;height: 490px\" border=\"1\">\n<tbody>\n<tr style=\"height: 24px\">\n<td style=\"width: 26.5835%;text-align: center;height: 24px\"><strong>payload<\/strong><\/td>\n<td style=\"width: 73.4165%;text-align: center;height: 24px\"><strong>Aim<\/strong><\/td>\n<\/tr>\n<tr style=\"height: 48px\">\n<td dir=\"ltr\" style=\"width: 26.5835%;height: 48px;text-align: center\"><span style=\"color: #0000ff\"><em><strong>@download<\/strong><\/em><\/span><\/td>\n<td style=\"width: 73.4165%;height: 48px;text-align: right\">Downloading one or more files from the malware server and creating them on the victim&#8217;s system by calling the api\/v1\/fetch function.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 26.5835%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em><strong>@upload<\/strong><\/em><\/span><\/td>\n<td style=\"width: 73.4165%;height: 24px;text-align: right\">Uploading one or more existing files from the victim&#8217;s system as determined by the malware server. These files are sent by calling the api\/v1\/files\/ function.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 26.5835%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em><strong>@cd<\/strong><\/em><\/span><\/td>\n<td style=\"width: 73.4165%;height: 24px;text-align: right\">Extracting a list of contents in a specified directory by calling the api\/v1\/explorer\/ function.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 26.5835%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em><strong>@psnapshot<\/strong><\/em><\/span><\/td>\n<td style=\"width: 73.4165%;height: 24px;text-align: right\">\u00a0Extracting the list of system processes by calling the api\/v1\/psnapshot\/ function.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 26.5835%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em><strong>@fetch<\/strong><\/em><\/span><\/td>\n<td style=\"width: 73.4165%;height: 24px;text-align: right\">Downloading the file<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 26.5835%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em><strong>@execute<\/strong><\/em><\/span><\/td>\n<td style=\"width: 73.4165%;height: 24px;text-align: right\">Executing commands received from the server on the victim&#8217;s system.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 26.5835%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em><strong>@rm<\/strong><\/em><\/span><\/td>\n<td style=\"width: 73.4165%;height: 24px;text-align: right\">Deleting the file or files specified by the malware server from the victim&#8217;s system.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td dir=\"ltr\" style=\"width: 26.5835%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em><strong>@rename<\/strong><\/em><\/span><\/td>\n<td style=\"width: 73.4165%;height: 24px;text-align: right\">Renaming one or more of the victim&#8217;s system files to the new names specified by the malware server.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center\">Table 2- List of Malware Tasks Received from the Server<\/p>\n<p>&nbsp;<\/p>\n<p>While executing the received tasks and establishing the necessary communications, the malware reports the result of its task by calling the &#8220;<em>api\/v1\/task\/&#8221;<\/em> function, then requests a new task again.<br \/>\nFor example, in the received sample task presented below, in the payload content, the server has sent the<span style=\"color: #0000ff\"> @cd &#8220;C:\\\\&#8221; <\/span> command to the malware to execute. The <em>{Qzpc}<\/em> expression in the following image is the encoded equivalent of the &#8220;<span style=\"color: #0000ff\">C:\\\\&#8221;<\/span> directory:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4154 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/06\/\u062a\u0635\u0648\u06cc\u0631-1-\u06cc\u06a9-\u0646\u0645\u0648\u0646\u0647-\u062f\u0631\u06cc\u0627\u0641\u062a-\u062a\u0633\u06a9-\u0627\u0632-\u0633\u0631\u0648\u0631.png\" alt=\" \u06cc\u06a9 \u0646\u0645\u0648\u0646\u0647 \u062f\u0631\u06cc\u0627\u0641\u062a \u062a\u0633\u06a9 \u0627\u0632 \u0633\u0631\u0648\u0631\" width=\"712\" height=\"330\" \/><\/p>\n<p style=\"text-align: center\">Figure 1 \u2013 A Sample Task Received from the Server<\/p>\n<p>In the figure above:<\/p>\n<ul>\n<li><em>Payload<\/em>: A command that the malware must execute on the victim&#8217;s system.<\/li>\n<li><em>ID:<\/em> The corresponding identifier for this task.<\/li>\n<li><em>Issued_to<\/em>: The value corresponding to the GUID created for the user.<\/li>\n<li><em>Host_ID:<\/em> The ID received from the malware by executing the `api\/v1\/heartbeat\/` function.<\/li>\n<li><em>Issued_name:<\/em> Corresponds to <em>`username@computer_name`.<\/em><\/li>\n<\/ul>\n<h2><\/h2>\n<h2>How to Deal with and Clean the System<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/11\/svg\/2705.svg\" alt=\"\u2705\" width=\"16\" height=\"16\" \/>Padvish Antivirus detects and removes this malware from the system. It is recommended to keep your operating system and antivirus up to date.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/11\/svg\/2705.svg\" alt=\"\u2705\" width=\"16\" height=\"16\" \/>To enhance security against the significant increase in cyberattacks, including advanced persistent threats, follow security recommendations and use Padvish Managed Detection and Response (MDR) services.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan Destruction Level: High Prevalence: Low &nbsp; Malware names Bot.Win32.Torzhok (Padvish) Gen:Variant.Adware.Symmi.87092 (bitdefender) &nbsp; What is Trojan? Trojan is a type of malware that disguises itself as clean and legitimate software and behaves totally like a useful and functional software, but when executed, it causes a lot of damage to the computer system.&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[43,79,80],"class_list":["post-1579","post","type-post","status-publish","format-standard","hentry","category-trojan","tag-trojan","tag-torzhok","tag-bot-win32-torzhok"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1579"}],"version-history":[{"count":1,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1579\/revisions"}],"predecessor-version":[{"id":1580,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1579\/revisions\/1580"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}