{"id":88,"date":"2020-11-18T09:56:55","date_gmt":"2020-11-18T09:56:55","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=88"},"modified":"2023-02-07T07:12:49","modified_gmt":"2023-02-07T07:12:49","slug":"trojan-bat-starter-cov","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2020\/11\/18\/trojan-bat-starter-cov\/","title":{"rendered":"Trojan.BAT.Starter.cov"},"content":{"rendered":"<h2>General Explanation<\/h2>\n<p><strong>Type:<\/strong> Trojan<\/p>\n<p><strong>General threat<\/strong>: low<\/p>\n<p><strong>Degree of destruction<\/strong>: average<\/p>\n<p><strong>Prevalence<\/strong>: low<\/p>\n<p><strong>Information leak:<\/strong> low<\/p>\n<h3>What is a Trojan?<\/h3>\n<p><span style=\"float: none;background-color: #ffffff;color: #333333;cursor: text;font-family: Georgia,'Times New Roman','Bitstream Charter',Times,serif;font-size: 16px;font-style: normal;font-variant: normal;font-weight: 400;letter-spacing: normal;text-align: left;text-decoration: none;text-indent: 0px\">Trojans are malware that revealed themselves in the format of an applicable and useful tool. Accordingly, the user downloads and installs them and infects the system without noticing that it is malware. Trojans, usually after installation, act as a backdoor so the hacker can remotely access the victim&#8217;s system. For instance, the malware we will analyze here seems to do an applicable and useful job, but it will install an unwanted application on the system.<\/span><\/p>\n<h3>What is BAT.starter.cov malware?<\/h3>\n<p>This malware family, as its name shows, will perform its desired actions by creating and running a batch file. This version of the malware is a type that by suing the coronavirus pandemic introduces itself as a functional application from WHO which will infect the system after being installed.<\/p>\n<h2>Technical Explanation<\/h2>\n<h3 id=\"ipt_kb_toc_559_4\">Signs of infection<\/h3>\n<p>After execution, malware with the help of the command line (cmd) attempts to copy its files in the %homedrive%\\COVID-19 and will restart the system. Then the following symptoms will be shown:<\/p>\n<ul>\n<li>Replacing the background of the Windows with a totally black and irreplaceable ground.<\/li>\n<li>Change the shape of the mouse cursor.<\/li>\n<li>Blocking access to the task manager<\/li>\n<li>Popping \u2013up the system infection alert window and reopens after closing it<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-92 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2020\/11\/Folder-with-malware.png\" alt=\"\" width=\"795\" height=\"600\" \/><\/p>\n<p>If the system is infected, turned off, or restarted, due to MBR destruction the use of the system is not possible and regardless of OS, the following page will be shown in boot:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-90 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2020\/11\/2.png\" alt=\"\" width=\"720\" height=\"400\" \/><\/p>\n<h3>Explain function<\/h3>\n<ol>\n<li><strong>The main file of the malware:<\/strong> this file has the duty to copy created files in the COVID-19 folder and run the script of the program and does not do anything else.<\/li>\n<li><strong>mainWindow.exe file:<\/strong> this application is only for showing the malware message<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-91 alignnone\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2020\/11\/3.png\" alt=\"\" width=\"1193\" height=\"759\" \/><\/li>\n<li><strong>update.vbs script:<\/strong> this script will show its message, 2 minutes after execution:<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-94\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2020\/11\/4.png\" alt=\"\" width=\"1132\" height=\"58\" \/><\/li>\n<li><strong>Run.exe file:<\/strong> this execution file is relatively similar to malware in terms of behavior (not construction) and includes a script that will ensure the malware&#8217;s permanence by executing it.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-97 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2020\/11\/s.jpg\" alt=\"\" width=\"1163\" height=\"377\" \/>As you can see in the above script, the registry key related to ensuring malware execution will be seen again and the execution of the mainWindow file will be in an infinite loop.<\/li>\n<li><strong>end.exe file:<\/strong> the malicious part of this malware is this file, which after attaining necessary permission, the first block of the disk which contains BBR will be read and checked with the malware&#8217;s desired values.<\/li>\n<\/ol>\n<h2>How to deal with it and disinfect the system<\/h2>\n<p>To make sure that the system is safe, install <a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish antivirus<\/a> and keep its database file and scan it.<\/p>\n<p><strong>Methods of preventing phone infection:<\/strong><\/p>\n<ul>\n<li>Avoid downloading and installing any application from unauthorized resources\/markets.<\/li>\n<li>Note the requested permissions, when installing the mobile application.<\/li>\n<li>Continuously back up your saved data and files.<\/li>\n<li>Do not use an unofficial version of applications. Applications such as Telegram, and Instagram have many unofficial versions and most of them release through Telegram channels.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>General Explanation Type: Trojan General threat: low Degree of destruction: average Prevalence: low Information leak: low What is a Trojan? Trojans are malware that revealed themselves in the format of an applicable and useful tool. Accordingly, the user downloads and installs them and infects the system without noticing that it is malware. Trojans, usually after&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-88","post","type-post","status-publish","format-standard","hentry","category-trojan"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/88","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=88"}],"version-history":[{"count":11,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/88\/revisions"}],"predecessor-version":[{"id":1229,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/88\/revisions\/1229"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=88"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=88"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=88"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}