{"id":180,"date":"2020-11-21T12:25:23","date_gmt":"2020-11-21T12:25:23","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=180"},"modified":"2023-02-07T07:50:20","modified_gmt":"2023-02-07T07:50:20","slug":"worm-win32-brontok","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2020\/11\/21\/worm-win32-brontok\/","title":{"rendered":"Worm.Win32.Brontok"},"content":{"rendered":"<h2>General Explanation<\/h2>\n<p><strong>Type:<\/strong> Worm<\/p>\n<p><strong>Degree of destruction<\/strong>: high<\/p>\n<p><strong>Prevalence<\/strong>: average<\/p>\n<p><strong>Names of the malware:<\/strong><\/p>\n<ul>\n<li>Worm.Win32.Brontok.a<\/li>\n<li>Worm.Win32.Brontok.AP<\/li>\n<li>Worm.Win32.Brontok.fn<\/li>\n<li>Worm.Win32.Brontok.Qq<\/li>\n<li>Worm.Win32.Brontok.jlVB<\/li>\n<li>Worm.Win32.Brontok.proc<\/li>\n<li>Worm.Win32.Brontok.mm<\/li>\n<\/ul>\n<h3>What is the Worm?<\/h3>\n<p>Computer worms such as Brontok are types of malware that are capable of reproduction. For permanence, worms set ways to maintain the infection in each system boot. The prominent feature of worms is in their distribution which is generally performed through portable drives and shared directories in the network.<\/p>\n<h3>What is Brontok malware?<\/h3>\n<p>This malware which enters in victim&#8217;s system aim to perform DDoS attacks, in its first execution will execute copies of itself in different place of the system and creates registry keys for its maintenance.<\/p>\n<p>This worm was released by email, share folder, and portable drivers. Also, it can disable antiviruses and other security programs in the victim&#8217;s system.<\/p>\n<h2>Technical Explanation<\/h2>\n<h3>Signs of infection<\/h3>\n<p>This malware creates its files with fake names similar to the names of systematic tools in the %appdata% path.<\/p>\n<ul>\n<li><code>\u201c%appdata%\\smss.exe\u201d<\/code><\/li>\n<li><code>\u201c%appdata%\\services.exe\u201d<\/code><\/li>\n<li><code>\u201c%appdata%\\lsass.exe\u201d<\/code><\/li>\n<li><code>\u201c%appdata%\\inetinfo.exe\u201d<\/code><\/li>\n<li><code>\u201c%appdata%\\csrss.exe\u201d<\/code><\/li>\n<li><code>\u201c%appdata%\\winlogon.exe\u201d<\/code><\/li>\n<\/ul>\n<p><strong>Also attempts to create the following files:<\/strong><\/p>\n<ul>\n<li><code>\u201c%windir%\\ShellNew\\sempalong.exe\u201d<\/code><\/li>\n<li><code>\u201c%windir%\\eksplorasi.exe\u201d<\/code><\/li>\n<li><code>\u201c%userprofile%\\Start Menu\\Programs\\Startup\\Empty.pif\u201d<\/code><\/li>\n<li><code>\u201c%userprofile%\\Templates\\Brengkolang.com\u201d<\/code><\/li>\n<li><code>\u201c[system32]\\&lt;username&gt;\u2019s Setting.scr\u201d<\/code><\/li>\n<li><code>\u201c[system32]\\drivers\\etc\\hosts-Denied By-&lt;username&gt;.com\u201d<\/code><\/li>\n<\/ul>\n<p dir=\"ltr\"><strong>This malware also creates its maintenance by correcting the Windows shell and registry RUN key:<\/strong><\/p>\n<ul>\n<li><code>\u201cHKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\Bron-Spizaetus\u201d<\/code><\/li>\n<li><code>Data:\u201d%windir%\\ShellNew\\sempalong.exe\u201d<\/code><\/li>\n<li><code>\u201cHKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell\u201d<\/code><\/li>\n<li><code>Data: Explorer.exe \u201c%windir%\\eksplorasi.exe\u201d<\/code><\/li>\n<li><code>\u201cHKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Tok-Cirrhatus\u201d<\/code><\/li>\n<li><code>Data: \u201c%appdata%\\smss.exe\u201d<\/code><\/li>\n<li><code>\u201cHKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableCMD\u201d<\/code><\/li>\n<\/ul>\n<p dir=\"ltr\"><strong>Explaining the function of malware files:\u00a0<\/strong><\/p>\n<p dir=\"ltr\">This malware enters the victim&#8217;s system and aims to perform a DDoS attack.<\/p>\n<p dir=\"ltr\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-181 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2020\/11\/Brontok-1-1.png\" alt=\"\" width=\"793\" height=\"311\" \/><\/p>\n<p dir=\"ltr\">After creating maintenance for itself, the fake smss.exe file will be executed this process will execute other copies of the main process and in between, will remove all tasks which the system has built and then create a task aimed to execute one of its copies named Brengkolang.com; this task will execute the malware in every day of the week and on a certain time.<\/p>\n<p dir=\"ltr\">In the following, a process name csrss (which is a copy of the main malware) will kill the following processes.<\/p>\n<ul>\n<li>mcvsescn.exe<\/li>\n<li>poproxy.exe<\/li>\n<li>avgemc.exe<\/li>\n<li>ccapps.exe<\/li>\n<li>tskmgr.exe<\/li>\n<li>syslove.exe<\/li>\n<li>xpshare.exe<\/li>\n<li>riyani_jangkaru.exe<\/li>\n<li>systray.exe<\/li>\n<\/ul>\n<p dir=\"ltr\">In the above list, you can see the names of all processes which belong to antiviruses. For example, mcvsescn.exe belongs to McAfee VirusScan E-mail and also poproxy.exe file belongs to Norton Antivirus protection suite.<\/p>\n<p dir=\"ltr\">Also do not send emails to addresses that involve the following strings.<\/p>\n<p dir=\"ltr\"><span style=\"color: #ff0000\">SECURE \u2013 SUPPORT \u2013 MASTER \u2013 MICROSOFT \u2013 VIRUS \u2013 HACK \u2013 CRACK \u2013 LINUX \u2013 AVG \u2013 GRISOFT \u2013 CILLIN \u2013 SECURITY \u2013 SYMANTEC \u2013 ASSOCIATE \u2013 VAKSIN \u2013 NORTON \u2013 NORMAN \u2013 PANDA \u2013 SOFT \u2013 SPAM \u2013 BLAH \u2013 YOUR \u2013 SOME \u2013 ASDF \u2013 @. \u2013 .@ \u2013 WWW \u2013 VAKSIN \u2013 DEVELOP \u2013 PROGRAM \u2013 SOURCE \u2013 NETWORK \u2013 UPDATE \u2013 TEST \u2013 .. \u2013 XXX \u2013 SMTP \u2013 EXAMPLE \u2013 CONTOH \u2013 INFO@ \u2013 BILLING@ \u2013.ASP \u2013 .PHP \u2013 .HTM \u2013 .EXE \u2013 .JS \u2013 .VBS \u2013 DOMAIN \u2013 HIDDEN \u2013 DEMO \u2013 DEVELOP \u2013 FOO@ \u2013 KOMPUTER \u2013 SENIOR \u2013 DARK \u2013 BLACK \u2013 BLEEP \u2013 FEEDBACK \u2013 IBM. \u2013 INTEL. \u2013 MACRO \u2013 ADOBE \u2013 RECIPIENT \u2013 SERVER \u2013 PROXY \u2013 ZEND \u2013 ZDNET \u2013 CNET \u2013 DOWNLOAD \u2013 HP. \u2013 XEROX \u2013 CANON \u2013 SERVICE \u2013 ARCHIVE \u2013 NETSCAPE \u2013 MOZILLA \u2013 OPERA \u2013 NOVELL \u2013 NEWS \u2013 UPDATE \u2013 RESPONSE \u2013 OVERTURE \u2013 GROUP \u2013 GATEWAY \u2013 RELAY \u2013 ALERT \u2013 SEKUR \u2013 CISCO \u2013 LOTUS \u2013 MICRO \u2013 TREND \u2013 SIEMENS \u2013 FUJITSU \u2013 NOKIA \u2013 W3. \u2013 NVIDIA \u2013 APACHE \u2013 MYSQL \u2013 POSTGRE \u2013 SUN. \u2013 GOOGLE \u2013 SPERSKY \u2013 ZOMBIE \u2013 ADMIN \u2013 AVIRA \u2013 AVAST \u2013 TRUST \u2013 ESAVE \u2013 ESAFE \u2013 PROTECT \u2013 ALADDIN \u2013 ALERT \u2013 BUILDER \u2013 DATABASE \u2013 AHNLAB \u2013 ROLAND \u2013 ESCAN \u2013 HAURI \u2013 NOD32 \u2013 SYBARI \u2013 ANTIGEN \u2013 ROBOT \u2013 ALWIL \u2013 YAHOO \u2013 COMPOSE \u2013 COMPUTE \u2013 SECUN \u2013 SPYW \u2013 REGIST \u2013 FREE \u2013 BUG \u2013 MATH \u2013 LAB \u2013 IEEE \u2013 KDE \u2013 TRACK \u2013 INFORMA \u2013 FUJI \u2013 @MAC \u2013 SLACK \u2013 REDHA \u2013 SUSE \u2013 BUNTU \u2013 XANDROS \u2013 @ABC \u2013 @123 \u2013 LOOKSMART \u2013 SYNDICAT \u2013 ELEKTRO \u2013 ELECTRO \u2013 NASA \u2013 LUCENT \u2013 TELECOM \u2013 STUDIO \u2013 SIERRA \u2013 USERNAME \u2013 IPTEK \u2013 CLICK \u2013 SALES \u2013 PROMO<\/span><\/p>\n<p dir=\"ltr\">Malware will monitor the title of the opened windows in the system. Each window that contains the following title results in a system reboot.<\/p>\n<ul>\n<li>REGISTRY<\/li>\n<li>SYSTEM CONFIGURATION<\/li>\n<li>COMMAND PROMPT<\/li>\n<li>.EXE<\/li>\n<li>SHUT DOWN<\/li>\n<li>SCRIPT HOST<\/li>\n<li>LOG OFF WINDOWS<\/li>\n<li>KILLBOX<\/li>\n<li>TASKKILL<\/li>\n<li>TASK KILL<\/li>\n<li>HIJACK<\/li>\n<li>BLEEPING<\/li>\n<\/ul>\n<p dir=\"ltr\">As said before, malware enters the system aiming for a DDoS attack and the attack of this malware was the &#8220;ping of death&#8221; which by sending ICMP packets to the desired server with a 747-byte buffer will interfere in server servicing.<\/p>\n<p dir=\"ltr\"><strong>The malware will release in three ways:<\/strong><\/p>\n<ol>\n<li>By portable drives\n<p style=\"padding-left: 30px\">As you can see in the following image, malware will create a copy of itself in every folder with the name of the user&#8217;s information (for example data+username).<\/p>\n<p dir=\"ltr\" style=\"padding-left: 30px\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-182 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2020\/11\/Flash.usb_-1.png\" alt=\"\" width=\"606\" height=\"404\" \/><\/p>\n<\/li>\n<li>It will attach itself to emails and will send them.<\/li>\n<li>It will copy itself into the shared folders of the system.<\/li>\n<\/ol>\n<h2>How to deal with it and disinfect the system<\/h2>\n<p><a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish Antivirus<\/a> by using a real-time scanner of shared drives and folders in the network will monitor the examples of this malware and disinfect them. Also having UMP capability which is a part of behavioral protection, will prevent the system from being infected by a portable driver. So to prevent infection from this method of transferring such as this malware, it is recommended to install Padvish.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>General Explanation Type: Worm Degree of destruction: high Prevalence: average Names of the malware: Worm.Win32.Brontok.a Worm.Win32.Brontok.AP Worm.Win32.Brontok.fn Worm.Win32.Brontok.Qq Worm.Win32.Brontok.jlVB Worm.Win32.Brontok.proc Worm.Win32.Brontok.mm What is the Worm? Computer worms such as Brontok are types of malware that are capable of reproduction. For permanence, worms set ways to maintain the infection in each system boot. The prominent feature&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-180","post","type-post","status-publish","format-standard","hentry","category-worm"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/180","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=180"}],"version-history":[{"count":11,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/180\/revisions"}],"predecessor-version":[{"id":1244,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/180\/revisions\/1244"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=180"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=180"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=180"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}