{"id":99,"date":"2020-11-18T10:01:52","date_gmt":"2020-11-18T10:01:52","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=99"},"modified":"2023-02-07T07:13:48","modified_gmt":"2023-02-07T07:13:48","slug":"trojan-java-adwind","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2020\/11\/18\/trojan-java-adwind\/","title":{"rendered":"Trojan.JAVA.Adwind"},"content":{"rendered":"<h2>General Explanation<\/h2>\n<p><strong>Type<\/strong>: Trojan<\/p>\n<p><strong>Degree of destruction<\/strong>: average<\/p>\n<p><strong>Prevalence<\/strong>: average<\/p>\n<h3>What is a Trojan?<\/h3>\n<p><span style=\"float: none;background-color: #ffffff;color: #333333;cursor: text;font-family: Georgia,'Times New Roman','Bitstream Charter',Times,serif;font-size: 16px;font-style: normal;font-variant: normal;font-weight: 400;letter-spacing: normal;text-align: left;text-decoration: none;text-indent: 0px\">Trojans are malware that revealed themselves in the format of an applicable and useful tool. Accordingly, the user downloads and installs them and infects the system without noticing that it is malware. Trojans, usually after installation, act as a backdoor so the hacker can remotely access the victim&#8217;s system. For instance, the malware we will analyze here seems to do an applicable and useful job, but it will install an unwanted application on the system.<\/span><\/p>\n<h3>What is Adwind malware?<\/h3>\n<p>Adwind Trojan distributed by using Java instructions and in form of JAR files is able to steal user\u2019s information. Attackers use this malware for collecting and extracting system data as well as remote control of the infected system. Data that this malware will be collected from the victim\u2019s system which is generally from input\/output devices such as a keyboard, mouse, and monitor, and is able to secrete user\u2019s data and interface user\u2019s access to data.<\/p>\n<h2>Technical Explanation<\/h2>\n<h3 id=\"ipt_kb_toc_515_4\">Signs of infection<\/h3>\n<ul>\n<li>Creating files with exe and java.exe titles in the following path:<\/li>\n<\/ul>\n<p style=\"padding-left: 60px\"><code>\"Appdata%\\Oracle\\bin%\"<\/code><\/p>\n<ul>\n<li>Defining Debugger value in the registry for the systematic applications which result in the user being unable to use it. This value defines the following path by adjusting the exe value as Debugger:<\/li>\n<\/ul>\n<p style=\"padding-left: 60px\"><code>\"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\"<\/code><\/p>\n<ul>\n<li>Disabling Taskmanager tool of Windows by setting the value for DisableTaskMgr in the following path:<\/li>\n<\/ul>\n<p style=\"padding-left: 60px\"><code>\"SOFTWARE\\Policies\\Microsoft\\Windows NT\\\\SystemRestore\"<\/code><\/p>\n<p style=\"padding-left: 60px\"><code>value name: DisableConfig<\/code><\/p>\n<p style=\"padding-left: 60px\"><code>data: 1<\/code><\/p>\n<p style=\"padding-left: 60px\"><code>\"SOFTWARE\\Policies\\Microsoft\\Windows NT\\SystemRestore\"<\/code><\/p>\n<p style=\"padding-left: 60px\"><code>value name: DisableSR<\/code><\/p>\n<p style=\"padding-left: 60px\"><code>data: 1<\/code><\/p>\n<ul>\n<li>Adjusting the following value in the registry;<\/li>\n<\/ul>\n<p style=\"padding-left: 60px\"><code>\"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\"<\/code><\/p>\n<p style=\"padding-left: 60px\"><code>valueName: ConsentPromptBehaviorAdmin<\/code><\/p>\n<p style=\"padding-left: 60px\"><code>data: 0<\/code><\/p>\n<p>This option let the malware perform an operation without admin validation.<\/p>\n<ul>\n<li>Creating a folder named JAVA in system drivers and transferring files with a special extension (such as image files, documentation and etc.) into the mentioned folder and secreting it. This causes the user\u2019s data to hide out of the user\u2019s sight and believed they&#8217;re gone.<\/li>\n<\/ul>\n<h2>How to deal with it and disinfect the system<\/h2>\n<p><a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish antivirus<\/a> will detect and delete this malware. To prevent entering these kinds of malware into the system, it is recommended to avoid clicking on suspicious links and scan all attached files in emails. Also, always keep your OS and antivirus up to date, if possible.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>General Explanation Type: Trojan Degree of destruction: average Prevalence: average What is a Trojan? Trojans are malware that revealed themselves in the format of an applicable and useful tool. Accordingly, the user downloads and installs them and infects the system without noticing that it is malware. Trojans, usually after installation, act as a backdoor so&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-99","post","type-post","status-publish","format-standard","hentry","category-trojan"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/99","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=99"}],"version-history":[{"count":6,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/99\/revisions"}],"predecessor-version":[{"id":1230,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/99\/revisions\/1230"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=99"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=99"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=99"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}