Trojan.PS1.SORVEPOTEL.JRN (DNP)
Trojan:PowerShell/SorvePotel.GNF!MTB (MICROSOFT)
Windows


Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It connects to certain websites to send and receive information.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan drops the following files:
- C:\temp\{6 Random Characters}-{8 Random Characters}-{3 Random Characters}.zip
- C:\temp\wppconnect-wa.js → legitimate script for WhatsApp
- C:\temp\chromedriver.zip → If Chrome is installed. Deleted afterwards
- C:\temp\chromedriver.exe → legitimate Chrome driver.
- C:\temp\msedgedriver.zip → If Edge is installed. Deleted afterwards
- C:\temp\msedgedriver.exe → legitimate Edge driver
- C:\temp\geckodriver.zip → If Firefox is installed, deleted afterwards
- C:\temp\geckodriver.exe → legitimate Firefox driver
It adds the following processes:
- powershell.exe -Command Install-PackageProvider -Name NuGet -MinimumVersion 2.8.5.201 -Force -Scope CurrentUser
- powershell.exe -Command Set-PSRepository -Name PSGallery -InstallationPolicy Trusted
- powershell.exe -Command Install-Module -Name Selenium -Force -Scope CurrentUser -AllowClobber -SkipPublisherCheck
- powershell.exe -Command Import-Module Selenium
- chrome.exe --user-data-dir=C:\temp\Selenium_Chrome --profile-directory=Default --headless=new --disable-gpu --no-sandbox --disable-blink-features=AutomationControlled
- msedge.exe --user-data-dir=C:\temp\Selenium_Edge --profile-directory=Default --headless=new --disable-gpu --disable-blink-features=AutomationControlled
- firefox.exe -profile C:\temp\Selenium_Firefox --headless
It creates the following folders:
- C:\temp\Selenium_Google Chrome
- C:\temp\Selenium_Microsoft Edge
- C:\temp\Selenium_Mozilla Firefox
Process Termination
This Trojan terminates the following processes if found running in the affected system's memory:
- chrome.exe
- chromedriver.exe
- msedge.exe
- msedgedriver.exe
- firefox.exe
- geckodriver.exe
Download Routine
This Trojan connects to the following URL(s) to download its component file(s):
- https://{BLOCKED}onstudioclayworks.online/arquivoatualizado/gera.php
- https://googlechromelabs.{BLOCKED}b.io/chrome-for-testing/latest-versions-per-milestone-with-downloads.json
- https://msedgedriver.{BLOCKED}oft.com/{Microsoft Edge Version}/edgedriver_win64.zip
- https://msedgedriver.{BLOCKED}oft.com/{Microsoft Edge Base Version}/edgedriver_win64.zip
- https://msedgedriver.{BLOCKED}oft.com/{Microsoft Edge Stable Version}/edgedriver_win64.zip where stable versions are:
- {BLOCKED}.{BLOCKED}.3614.0
- {BLOCKED}.{BLOCKED}.3578.0
- {BLOCKED}.{BLOCKED}.3537.0
- {BLOCKED}.{BLOCKED}.3498.0
Information Theft
This Trojan gathers the following data:
- System Information:
- Computer Name
- Operating System version
- Browser Session Data:
- WhatsApp Web authentication tokens
- WhatsApp contact list with names and phone numbers
- Active browser sessions from Chrome, Edge, or Firefox
Other Details
This Trojan connects to the following website to send and receive information:
- https://{BLOCKED}opeaks.com/api/log.php
- https://{BLOCKED}opeaks.com/api/config.php
- https://{BLOCKED}opeaks.com/api/contacts.php
- https://{BLOCKED}opeaks.com/api/api.php
- https://web.{BLOCKED}pp.com/
It does the following:
- It hijacks browser sessions by copying profile data to access WhatsApp Web.
- It operates in headless mode to run browser invisibly without UI windows.
- It extracts contact lists from victim's WhatsApp account filtering only individual contacts.
- It sends malicious ZIP files to all WhatsApp contacts with personalized greeting messages.
- It uses WPP-JS library to automate WhatsApp Web messaging.
- It pings its C2 server every 30 seconds for configuration updates.
- It logs all activities in real-time to C2 server for operator monitoring
- It copies profile-related files from the following web browser:
- Chrome: %AppDataLocal%\Google\Chrome\User Data
- Local State folder
- Default folder
- IndexedDB
- Local Storage
- Session Storage
- Service Worker
- Cache
- Code Cache
- blob_storage
- databases
- File System
- GPUCache
- Cookies
- Preferences
- Secure Preferences
- Edge: %AppDataLocal%\Microsoft\Edge\User Data
- Local State folder
- Default folder
- IndexedDB
- Local Storage
- Session Storage
- Service Worker
- Cache
- Code Cache
- blob_storage
- databases
- File System
- GPUCache
- Cookies
- Preferences
- Secure Preferences
- Firefox: %AppData%\Mozilla\Firefox\Profiles
- {Profile Name}.FullName
- The profile-related data are copied to:
- C:\temp\Selenium_{Browser Name}
- Google Chrome
- Microsoft Edge
- Mozilla Firefox
SOLUTION
Step 1
Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.
Step 2
Note that not all files, folders, and registry keys and entries are installed on your computer during this malware's/spyware's/grayware's execution. This may be due to incomplete installation or other operating system conditions. If you do not find the same files/folders/registry information, please proceed to the next step.
Step 3
Search and delete these files
Step 4
Search and delete these folders
Did this description help? Tell us how we did.


