{"id":266,"date":"2020-12-05T05:17:58","date_gmt":"2020-12-05T05:17:58","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=266"},"modified":"2023-02-07T08:32:55","modified_gmt":"2023-02-07T08:32:55","slug":"worm-win32-neutrino","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2020\/12\/05\/worm-win32-neutrino\/","title":{"rendered":"Worm.Win32.Neutrino"},"content":{"rendered":"<h2>General Explanation<\/h2>\n<p><strong>Type:<\/strong> Worm<\/p>\n<p><strong>Degree of destruction<\/strong>: High<\/p>\n<p><strong>Prevalence:<\/strong> High<\/p>\n<h3>What is the Worm?<\/h3>\n<p>Computer worms such as Neutrino are types of malware that can automatically reproduce themselves. For permanence, worms set ways to maintain infection in the system in every boot. The prominent feature of worms is their distribution method which is generally through portable drives and shared directories in the network.<\/p>\n<h3>What is Neutrino malware?<\/h3>\n<p>Neutrino malware provides a basis for bitcoin miners and Ransomware. The most important detected Ransomware in this way is Gand Crab malware.<\/p>\n<p>This malware will run multiple bitcoin miner processes after the execution that will engage the system CPU and slows the OS.<\/p>\n<h2>Technical Explanation<\/h2>\n<p>One of the distribution methods of this malware is a portable drive as such all victim&#8217;s existing files and portable drives will be transferred to a directory named &#8220;_&#8221; and copy a version of itself in this directory. In some of these malware examples and the path of the portable drive, two files &#8220;deviceconfigmanager.vbs and autorun.inf&#8221; will be placed as well as an Ink file in every example in the path of the portable drive. All files and directories except Ink file are hidden and system type. Hence, the only thing which can be seen in it is the Ink file which will be executed with a click, when you connect the portable drive to the system.<\/p>\n<p>First, malware will provide a basis for its permanence and then acts like a bot and will connect to its server; based on the instructions it received from its server, it will provide a basis for the creation and execution of bitcoins. By executing bitcoins, the user&#8217;s system will extensively be slow that which is due to too much use of CPU by the malware processes.<\/p>\n<p>This malware is sensitive to several related processes to\u00a0VMWare-VirtualBox-Citrix Xen Server it will end its execution if it runs on one of these Virtual machines.<\/p>\n<h3><strong>Signs of infection\u00a0<\/strong><\/h3>\n<p>Each of the following files can build into the victim&#8217;s system separately:<\/p>\n<ul>\n<li><code>[SystemRoot]:\\\\Windows\\\\M-505059720970246082475082628448545\\\\winmgr.exe<\/code><\/li>\n<li><code>[SystemRoot]:\\\\Windows\\\\M-505059720970246082475082628448545\\\\winsvc.exe<\/code><\/li>\n<li><code>[SystemRoot]:\\\\Windows\\\\M-505059720970246082475082628448545\\\\winsvcs.exe<\/code><\/li>\n<li><code>[SystemRoot]:\\\\Windows\\\\M-505059720970246082475082628448545\\\\winsecmgr.exe<\/code><\/li>\n<\/ul>\n<p dir=\"ltr\">The directory name from &#8220;M-&#8221; to the end of the phrase is random. In some examples, the name of the directory will begin with &#8220;T-&#8220;.<\/p>\n<p dir=\"ltr\">In the new observed examples, the name of the directory is just a random collection of numbers, and the letters &#8220;M-&#8221; and &#8220;T-&#8221; have been removed.<\/p>\n<p dir=\"ltr\">In the new examples that were recently analyzed, malware will deactivate the system restore by changing registries.<\/p>\n<p dir=\"ltr\"><code>HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore<\/code><\/p>\n<p dir=\"ltr\"><code>ValueName = DisableSR<\/code><\/p>\n<p dir=\"ltr\"><code>Generally, the malware process will be run by the following name:<\/code><\/p>\n<p dir=\"ltr\"><code>winsvcs.exe-winsvc.exe-winmgr.exe-winsecmgr.exe<\/code><\/p>\n<p dir=\"ltr\">If the following names&#8217; parental processes are not explorer.exe and services.exe, it can be observed in the current system processes that may be the system is infected by the bitcoin files which are downloaded from the infected malware.<\/p>\n<p dir=\"ltr\"><code>\u201csvchost.exe\u201d,\u201dnotepad.exe\u201d,\u201dwinmgr.exe\u201d,\u201dwuapp.exe\u201d<\/code><\/p>\n<p dir=\"ltr\">The built-up registry path for malware permanence:<\/p>\n<p dir=\"ltr\"><code>HKEY_CURRENT_USER\\\\SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Run<\/code><br \/>\n<code>ValueName = \u201cMicrosoft Windows Manager\u201d OR \u201cMicrosoft Windows Service\u201d OR \u201cMicrosoft Windows Services\u201d OR \u201cMicrosoft Windows Updates\u201d OR \u201cMicrosoft Windows Updates Manager\u201d OR \u201cMicrosoft Windows Driver\u201d<\/code><br \/>\n<code>Data=%User Profile%\\[RandomName]\\winsvcs.exe<\/code><br \/>\n<code>OR<\/code><br \/>\n<code>[SystemRoot]:\\Windows\\]\\[RandomName]\\winsvcs.exe<\/code><\/p>\n<p dir=\"ltr\">In the new version of this malware in Windows 10, the malware will manipulate the registries related to Windows Defender. These changes may interfere with the Windows Defender function.<\/p>\n<p dir=\"ltr\"><code>HKLM\\Software\\Policies\\Microsoft\\Windows\u202c\u202c \u202b\u202aDefender\\Real-Time Protection<\/code><\/p>\n<p dir=\"ltr\"><code>Value:\u00a0DisableScanOnRealtimeEnable OR DisableOnAccessProtection OR\u00a0DisableBehaviorMonitoring<\/code><\/p>\n<p dir=\"ltr\">This malware, also, infects the directories and share drives such as portable drives.<\/p>\n<p dir=\"ltr\">In the new versions of this malware, a massive volume of traffic will exist from port 5900 of the infected system. Malware tries to connect with a huge number of IPs from this port. Surveys show that some of these IPs belong to the malware server.<\/p>\n<p dir=\"ltr\"><strong>This malware continuously updates itself<\/strong><\/p>\n<h2>How to deal with it and disinfect the system<\/h2>\n<h3><span style=\"float: none;background-color: #ffffff;color: #333333;cursor: text;font-family: Georgia,'Times New Roman','Bitstream Charter',Times,serif;font-size: 16px;font-style: normal;font-variant: normal;font-weight: 400;letter-spacing: normal;text-align: left;text-decoration: none;text-indent: 0px\">By UMP capability which is a part of behavioral protection, <a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish<\/a> can prevent the system from infection through a portable drive. Therefore, to prevent infection to all types of malware that transfer through portable drives such as Neutrino malware, it is recommended to install Padvish and prevent malware from entering and infecting the system.<\/span><\/h3>\n<p dir=\"ltr\"><strong>If your system is infected with Neutrino malware, follow these steps:<\/strong><\/p>\n<ol>\n<li style=\"min-height: 1.5em\">Install Padvish on your system<\/li>\n<li style=\"min-height: 1.5em\">Connect the infected portable drive to your system<\/li>\n<li style=\"min-height: 1.5em\">Scan the portable drive with Padvish to disinfect the drive and your infected system.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>General Explanation Type: Worm Degree of destruction: High Prevalence: High What is the Worm? Computer worms such as Neutrino are types of malware that can automatically reproduce themselves. For permanence, worms set ways to maintain infection in the system in every boot. The prominent feature of worms is their distribution method which is generally through&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[15],"class_list":["post-266","post","type-post","status-publish","format-standard","hentry","category-worm","tag-ump"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/266","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=266"}],"version-history":[{"count":10,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/266\/revisions"}],"predecessor-version":[{"id":1260,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/266\/revisions\/1260"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=266"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=266"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=266"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}