Analysis by: Maureen Reyes

ALIASES:

PUA:Win32/Softcnapp (Microsoft)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File Size: 6,219,552 bytes
File Type: EXE
Memory Resident: Yes
Initial Samples Received Date: 01 Jul 2019

Arrival Details

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This Trojan creates the following folders:

  • %Program Files%\Common Files\Clover

(Note: %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).)

Other System Modifications

This Trojan adds the following registry keys:

HKEY_LOCAl_MACHINE\Software
Clovermgr =

HKEY_LOCAL_MACHINE\CurrentControlSet001\Services
HCloverService =

HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
Parameters =

It adds the following registry entries:

HKEY_LOCAl_MACHINE\Software\Clovermgr
ServiceDescription = "Clover 自动更新服务"

HKEY_LOCAl_MACHINE\Software\Clovermgr
ServiceDisplayName = "clover_service"

HKEY_LOCAl_MACHINE\Software\Clovermgr
ServiceDll = %Program Files%\Clover\CloverSvc.dll"

HKEY_LOCAl_MACHINE\Software\Clovermgr
ServiceName = "HCloverService"

HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
Description = "Clover 自动更新服务"

HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
DisplayName = "clover_service"

HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
ErrorControl = "1"

HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
ImagePath = "C:\Windows\system32\svchost.exe -k HCloverService"

HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
ObjectName = "LocalSystem"

HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
Start = "2"

HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService
Type = "120"

HKEY_LOCAL_MACHINE\CurrentControlSet001\Services\
HCloverService\Parameters
ServiceDll = "%Program Files%\Clover\CloverSvc.dll"

Dropping Routine

This Trojan drops the following files:

  • %Program Files%\Common Files\Clover\Clover.ini
  • %User Temp%\my7xData.7z
  • %AppDataLocalLow%\Clover\Config\UseVestige.ini
  • %Program Files%\Clover\ico\baidu.png
  • %Program Files%\Clover\ico\jd.png
  • %Program Files%\Clover\ico\taobao.png
  • %Program Files%\Clover\reg,dat
  • %Program Files%\Clover\unreg.dat
  • %Program Files%\Clover\lang\lang_index.xml
  • %Program Files%\Clover\CloverInfo.ini
  • %Program Files%\Clover\appconfig.dat
  • %Program Files%\Clover\default.dat
  • %Program Files%\Clover\data\_.dat
  • %Program Files%\Clover\data\__.dat
  • %Program Files%\Clover\Clover.exe
  • %Program Files%\Clover\ClvAssist.exe
  • %Program Files%\Clover\ClvHelper.exe
  • %Program Files%\Clover\ClvUtil.exe
  • %Program Files%\Clover\SoftUpd.exe
  • %Program Files%\Clover\Uninst.exe
  • %Program Files%\Clover\CloverFlush.dll
  • %Program Files%\Clover\CLoverSvc.dll
  • %Program Files%\Clover\clover_dll.dll
  • %Program Files%\Clover\DuiLib_u.dll
  • %Program Files%\Clover\libeay32.dll
  • %Program Files%\Clover\login_ui.dll
  • %Program Files%\Clover\ssleay32.dll
  • %Program Files%\Clover\TabHelper32.dll
  • %Program Files%\Clover\TabHelper64.dll
  • %Program Files%\Clover\lang\uires_chs.dll
  • %Program Files%\Clover\lang\uires_de.dll
  • %Program Files%\Clover\lang\uires_en.dll
  • %Program Files%\Clover\lang\uires_es.dll
  • %Program Files%\Clover\lang\uires_fr.dll
  • %Program Files%\Clover\lang\uires_id.dll
  • %Program Files%\Clover\lang\uires_jp.dll
  • %Program Files%\Clover\lang\uires_ko.dll
  • %Program Files%\Clover\lang\uires_nl.dll
  • %Program Files%\Clover\lang\uires_pl.dll
  • %Program Files%\Clover\lang\uires_pt.dll
  • %Program Files%\Clover\lang\uires_ru.dll
  • %Program Files%\Clover\lang\uires_tw.dll
  • %Program Files%\Clover\UtilWnd.dll
  • %Program Files%\Clover官方网站.url
  • %Program Files%\Clover\Temp.xml
  • %Program Files%\Clover\temp.dat
  • %Program Files%\Clover\config.ini
  • %Common Programs%\Clover\官方网站.url
  • %Common Programs%\Clover\在线升级.lnk
  • %Common Programs%\Clover\Clover.lnk
  • %Common Programs%\Clover\卸载.lnk
  • %Desktop%\Clover.lnk

(Note: %Program Files% is the default Program Files folder, usually C:\Program Files in Windows 2000(32-bit), Server 2003(32-bit), XP, Vista(64-bit), 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit) , or C:\Program Files (x86) in Windows XP(64-bit), Vista(64-bit), 7(64-bit), 8(64-bit), 8.1(64-bit), 2008(64-bit), 2012(64-bit) and 10(64-bit).. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %AppDataLocalLow% is the LocalLow Application Data folder, which is usually C:\Users\{user name}\AppData\LocalLow on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %Common Programs% is the folder that contains common program groups for all users, which is usually C:\Documents and Settings\All Users\Start Menu\Programs on Windows 2000, XP, and Server 2003, or C:\ProgramData\Microsoft\Windows\Start Menu\Programs on Windows Vista, 7, and 8.. %Desktop% is the current user's desktop, which is usually C:\Documents and Settings\{User Name}\Desktop on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\Desktop on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)

Other Details

This Trojan connects to the following possibly malicious URL:

  • http://ocsp.{BLOCKED}gn.com/{random path}
  • http://sf.{BLOCKED}d.com/{random path}
  • http://tjv1.{BLOCKED}e.me/statistics/timestamp
  • http://config.{BLOCKED}e.me/{random path}