{"id":1581,"date":"2024-06-30T17:53:45","date_gmt":"2024-06-30T17:53:45","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1581"},"modified":"2024-07-10T11:23:30","modified_gmt":"2024-07-10T11:23:30","slug":"backdoor-win32-tofsee","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/06\/30\/backdoor-win32-tofsee\/","title":{"rendered":"Backdoor.Win32.Tofsee"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type:<\/strong> Trojan (backdoor)<br \/>\n<strong>Destruction Level:<\/strong> High<br \/>\n<strong>Prevalence:<\/strong> Medium<\/p>\n<h3><strong>Malware Name(s)<\/strong><\/h3>\n<ul>\n<li><strong>Backdoor.Win32.Tofsee (Padvish)<\/strong><\/li>\n<li><strong>A Variant Of Win32\/Tofsee.AJ (ESET)<\/strong><\/li>\n<li><strong>Backdoor:Win32\/Hostil.gen!A (Microsoft)<\/strong><\/li>\n<li><strong>HEUR:Trojan.Win32.Generic (Kaspersky)<\/strong><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify\">What is Backdoor Malware?<\/h3>\n<p style=\"text-align: justify\">Backdoors are applications designed to allow hackers to bypass the system security mechanism, granting unauthorized access to various system resources. Hackers can enter the system, with no concern for altered usernames or passwords, bypass authentication protocols. These applications come in various forms and hackers use them upon their needs to breach a system resource.<\/p>\n<p>&nbsp;<\/p>\n<h3>What is Tofsee Malware?<\/h3>\n<p>Tofsee is a type of malware used primarily to send spam emails via SMTP messages. The content of these emails is determined by the malware server and is commonly used for promotional spam. Another significant feature of Tofsee is its ability to download and execute executable file from the server. This malware variant is often packaged with several different crypters and ultimately injects the original malware into a svchost.exe process.<\/p>\n<h3 style=\"text-align: justify\"><\/h3>\n<h2>Technical Description<\/h2>\n<h3>Indicators of Compromise:<\/h3>\n<p>\u274c Changes the <span style=\"color: #0000ff\"><em>HKU\\*\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\shell<\/em><\/span>\u00a0key, usually set to <span style=\"color: #0000ff\">explorer.exe<\/span> by default, and adds the unpacked malware path at its end.<\/p>\n<p>\u274c Creates a key in\u00a0<span style=\"color: #0000ff\"><em>SOFTWARE\\Microsoft\\DeviceControl\\DevData<\/em><\/span> in `<em>HKLM<\/em>` or `<em>HKU<\/em>` with encrypted content.<\/p>\n<p>\u274c Presence of the following files:<\/p>\n<p style=\"text-align: left\"><span style=\"color: #0000ff\"><em>%WINDIR%\\Temp:temp<\/em><\/span><\/p>\n<p style=\"text-align: left\"><span style=\"color: #0000ff\"><em>UserProfile%\\Application Data\\desktop.ini:init%<\/em><\/span><\/p>\n<p>\u274c \u00a0If the above files cannot be created, the malware creates a file in this path:<br \/>\n<span style=\"color: #0000ff\"><em>UserProfile%\\Local Settings\\Application Data\\Microsoft\\Windows\\UsrClass.dat.tmp%<\/em><\/span><\/p>\n<p>&nbsp;<\/p>\n<h3>Performance Description<\/h3>\n<p>The malware consists of two main modules. The first\u00a0module identifies the mail server addresses:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-4184 aligncenter\" style=\"text-align: justify\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/06\/1-\u067e\u06cc\u062f\u0627-\u06a9\u0631\u062f\u0646-\u0622\u062f\u0631\u0633-Mail-Server-\u062f\u0627\u0645\u0646\u0647\u200c\u0647\u0627\u06cc-\u0632\u06cc\u0631.png\" alt=\"\u067e\u06cc\u062f\u0627 \u06a9\u0631\u062f\u0646 \u0622\u062f\u0631\u0633 Mail Server \u062f\u0627\u0645\u0646\u0647\u200c\u0647\u0627\u06cc \u0632\u06cc\u0631\" width=\"1225\" height=\"299\" \/><\/p>\n<p>The purpose of another module is to communicate with the Command and Control (C&amp;C) server to receive commands and settings, including\u00a0 creating a list of email addresses for spamming, email contents, and more. It can also send and execute applications on the victim&#8217;s server.<\/p>\n<p>This version of the malware uses the following addresses to connect to the C&amp;C server:<\/p>\n<p><span style=\"color: #0000ff\"><em>193[.]27[.]246[.]157 <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>212[.]95[.]32[.]52 <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>Rgtryhbgddtyh[.]biz <\/em><\/span><br \/>\n<span style=\"color: #0000ff\"><em>wertdghbyrukl[.]ch<\/em><\/span><\/p>\n<p>In the image below, the main functions of the malware is provided:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4185\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/06\/2-\u062a\u0648\u0627\u0628\u0639-\u0627\u0635\u0644\u06cc-\u0628\u062f\u0627\u0641\u0632\u0627\u0631-Tofsee.png\" alt=\" \u062a\u0648\u0627\u0628\u0639 \u0627\u0635\u0644\u06cc \u0628\u062f\u0627\u0641\u0632\u0627\u0631\u00a0Tofsee\" width=\"1402\" height=\"558\" \/><\/p>\n<h4><\/h4>\n<h3>Network Connection<\/h3>\n<p>The malware initially attempts to find the IP addresses of mail servers such as those of Microsoft, Yahoo, etc. In another thread, it connects to its C&amp;C server using the TCP protocol to receive and decrypt encrypted information. If the connection to the first address fails, the malware attempts to connect to other C&amp;C addresses after 5 minutes.<\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4186\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/06\/3-\u0631\u0648\u0634-\u0627\u0631\u062a\u0628\u0627\u0637-\u0628\u0627-\u0634\u0628\u06a9\u0647.png\" alt=\"\u0631\u0648\u0634 \u0627\u0631\u062a\u0628\u0627\u0637 \u0628\u0627 \u0634\u0628\u06a9\u0647\" width=\"1419\" height=\"589\" \/><\/p>\n<h2>How to deal with and clean the system<\/h2>\n<p>Padvish Antivirus detects and removes this malware. To prevent infection:<\/p>\n<p>\u2714\ufe0f\u00a0Keep your antivirus software up to date.<br \/>\n\u2714\ufe0f\u00a0Obtain files from reliable sources.<br \/>\n\u2714\ufe0f\u00a0Avoid clicking on suspicious links and scan email attachments with antivirus.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Trojan (backdoor) Destruction Level: High Prevalence: Medium Malware Name(s) Backdoor.Win32.Tofsee (Padvish) A Variant Of Win32\/Tofsee.AJ (ESET) Backdoor:Win32\/Hostil.gen!A (Microsoft) HEUR:Trojan.Win32.Generic (Kaspersky) &nbsp; What is Backdoor Malware? Backdoors are applications designed to allow hackers to bypass the system security mechanism, granting unauthorized access to various system resources. Hackers can enter the system, with no concern&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[53],"class_list":["post-1581","post","type-post","status-publish","format-standard","hentry","category-backdoor","tag-backdoor"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1581","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1581"}],"version-history":[{"count":3,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1581\/revisions"}],"predecessor-version":[{"id":1584,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1581\/revisions\/1584"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1581"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1581"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1581"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}