TrojanSpy.MSIL.XWORM.B
Windows


Threat Type: Trojan Spy
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. It may be dropped by other malware.
It does not have any propagation routine.
It executes commands from a remote malicious user, effectively compromising the affected system. It connects to a website to send and receive information.
It connects to certain websites to send and receive information.
TECHNICAL DETAILS
Arrival Details
This Trojan Spy arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It may be dropped by the following malware:
Installation
This Trojan Spy adds the following mutexes to ensure that only one of its copies runs at any one time:
- LqnCS8W05cPMjMaK
Propagation
This Trojan Spy does not have any propagation routine.
Backdoor Routine
This Trojan Spy executes the following commands from a remote malicious user:
- pong → Responds by sending a "pong" string and internal interval counter back to the C2 server.
- rec → Releases the mutex lock, restarts the application, and terminates the current process.
- CLOSE → Shuts down the socket connection and terminates the application.
- uninstall → Triggers the uninstaller routine to clean up malware artifacts.
- update → Triggers the uninstaller routine and updates the malware stub with a new payload version.
- DW → Executes a powershell script.
- FM → Loads and executes an assembly directly in memory.
- LN → Downloads a file from a specified URL into the temp directory, and executes it.
- Urlopen → Opens a specified URL visibly (through a browser).
- Urlhide → Sends a background HTTP GET request to a specified URL.
- PCShutdown → Forces an immediate system shutdown.
- PCRestart → Forces an immediate system restart.
- PCLogoff → Logs off the current Windows session.
- RunShell → Executes commands silently via the command shell.
- StartDDos → Starts a multi-threaded HTTP POST flood attack.
- StopDDos → Aborts the active DDoS attack thread.
- StartReport → Initiates active window monitoring of running processes.
- StopReport → Aborts the active window monitoring thread of running processes.
- Xchat → Sends an "Xchat" string and the ID generated using system information.
- Hosts → Reads and sends the contents of the Windows hosts file (%System%\drivers\etc\host).
- Shosts → Modifies Windows hosts file.
- DDos → Sends a "DDos" string back to the C2.
- plugin → Checks if the plugin exists in the registry. If stored, it decompresses and executes the plugin. Otherwise, it requests from C2 if missing.
- savePlugin → Saves the decoded plugin to the registry, then decompresses and executes it.
- RemovePlugins → Deletes the registry subkey containing the stored plugin data and sends a confirmation message.
- OfflineGet → Returns an error stating the offline keylogger is not enabled.
- $Cap → Captures the primary screen, resizes it into a JPEG thumbnail, and exfiltrates it.
(Note: %System% is the Windows system folder, where it usually is C:\Windows\System32 on all Windows operating system versions.)
It connects to the following websites to send and receive information:
- using TCP:
- range2021.{BLOCKED}.com:2021
- {BLOCKED}.{BLOCKED}.31.98:2021
- {BLOCKED}.{BLOCKED}.112.141:2021
It connects to the following URL(s) to send and receive commands from a remote malicious user:
- using TCP:
- range2021.{BLOCKED}.com:2021
- {BLOCKED}.{BLOCKED}.31.98:2021
- {BLOCKED}.{BLOCKED}.112.141:2021
Rootkit Capabilities
This Trojan Spy does not have rootkit capabilities.
Information Theft
This Trojan Spy gathers the following data:
- Processor count
- Username
- Computer name
- OS version and architecture
- Hard drive size of system drive
- Malware's last modification/installation date
- USB spread status → Checks whether the running executable's filename matches the designated USB propagation name (USB.exe).
- Administrator privileges → Determines if the current user process is running under the Windows Administrator role
- Installed antivirus products
- GPU information
- CPU information
- RAM information
- Webcam availability
- Active window titles → Monitored periodically during window reporting routines or sent via ping check-ins to track running applications.
- System time → Sent alongside ping check-in packets to track activity timestamps.
- Windows hosts file contents → Read directly from the system directory when requested by the C2.
Other Details
This Trojan Spy connects to the following website to send and receive information:
It does the following:
- It is a Lua script that masquerades as a .TIFF file. It needs LuaJIT or a Lua interpreter in order to be executed.
- When executed, loads a .NET assembly in memory and executes its payload.
It does not exploit any vulnerability.
SOLUTION
Step 1
Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.
Step 2
Scan your computer with your Trend Micro product to delete files detected as TrojanSpy.MSIL.XWORM.B. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information:
Did this description help? Tell us how we did.


