Trojan.X97M.INFOSTEAL.C
Trojan:Win32/Leonem (MICROSOFT); Trojan.GenericKD.81049774 (BITDEFENDER); Script:SNH-gen [Trj] (AVAST)
Windows


Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Trojan adds the following folders:
- %System Root%\1 temp
(Note: %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.)
It drops the following files:
- %User Temp%\{dd-mm-yy h-mm-ss}.htm
- %User Profile%\Documents\{number} PDF.pdf
- %System Root%\1 temp\{number} PDF.pdf
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name} on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.)
It adds the following processes:
- explorer "https://www.{BLOCKED}e.com/watch?v=X3jsnzyiInU"
- explorer "https://{BLOCKED}l.vn/huong-dan-khac-phuc-mot-so-loi-khi-gui-mail-hang-loat-bang-tien-ich-myexcel/"
Other System Modifications
This Trojan deletes the following files:
- %User Temp%\{dd-mm-yy h-mm-ss}.htm
(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)
It adds the following registry keys:
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliill
It adds the following registry entries:
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Gmail
Usename = {mail account user name in plain text}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Gmail
Pass = {mail account password in plain text}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Gmail
SMTP = {mail server address}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Gmail
Port = {mail server port}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Gmail
Send = {mail transport selector}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Gmail
ChuKyOutlook = {mail signature in HTML}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Gmail
ChuKyOutlookCoKo = {mail signature toggle}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Gmail
ChuKyGmail = {mail signature in HTML}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Gmail
ChuKyGmailCoKo = {mail signature toggle}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Gmail
ChonBanMienPhi = OK
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\MailVung
SVungNS = {source worksheet name}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\MailVung
CVungNS = {row count}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\OUTLOOKTEM
MacDinh = Outlook
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\OUTLOOKTEM
GUITHU = GUITHU
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\ChayLanDau
Kiemtra = OK
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Startup
TopKey = {key material}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Startup
TopKey2 = {key material}1234
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Startup
TopKey3 = 12345678123412
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Startup
TopKey16 = {key material}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Startup
CheckKey = {state value}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Startup
ChayKiemtraK = Roi
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\Startup
VAT1Top = 13
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\liliiliiliiili
ChonOutlook = {command string}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\liliiliiliiili
ChonGmail = {transport selector}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliilli\liliiliiliiili
TopKey16 = {character substitution table entry}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliill\Startup
Top = liliiliiliiiliil
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliill\Startup
SeriOcung{number} = {disk or motherboard serial number}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliill\Startup
MaMay{number} = {derived machine identifier}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliill\Startup
iakey123_{number} = {derived machine key}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliill\Startup
ibkey123_{number} = {derived machine key}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliill\Startup
ickey123_{number} = {derived machine key}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
liliiliiliiiliill\Startup
DuongDanMyVTV = {workbook folder}\MyVTVforExcel
Information Theft
This Trojan gathers the following data:
- Mail Account Data:
- mail account user name stored in HKEY_CURRENT_USER\Software\VB and VBA Program Settings\liliiliiliiiliilli\Gmail\Usename
- mail account password stored in plain text in HKEY_CURRENT_USER\Software\VB and VBA Program Settings\liliiliiliiiliilli\Gmail\Pass
- mail server address, port, and transport selector stored in HKEY_CURRENT_USER\Software\VB and VBA Program Settings\liliiliiliiiliilli\Gmail
- mail signatures stored in HKEY_CURRENT_USER\Software\VB and VBA Program Settings\liliiliiliiiliilli\Gmail
- Hardware Information:
- physical disk serial numbers
- motherboard serial number
- Workbook Data:
- recipient mail addresses
- carbon copy and blind carbon copy mail addresses
- mail subject lines
- mail body text
- attachment file names
- full contents of the active worksheet within the range A1:IV65000
- Local Files:
- mail message template files with the .msg file name extension referenced from worksheet cells
- attachment files located in %User Profile%\Documents
- attachment files located in C:\1 temp
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name} on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)
Stolen Information
This Trojan sends the gathered workbook data as mail messages through the mail client configured on the affected system.
It sends the gathered workbook data as mail messages through the mail server whose address, port, and transport are taken from the registry key HKEY_CURRENT_USER\Software\VB and VBA Program Settings\liliiliiliiiliilli\Gmail, using the stored mail account user name and password for authentication.
Other Details
This Trojan connects to the following possibly malicious URL:
- https://www.{BLOCKED}e.com/playlist?list=PLMaq39BTAz-IA8qlWjuV82Em9cjXSQ9A0
- https://www.{BLOCKED}e.com/playlist?list=PLMaq39BTAz-ISykhM4S-4xJm-Y8sfigx6
- https://www.{BLOCKED}e.com/playlist?list=PLMaq39BTAz-JN_-C82ug9JA4bNDZ7UT5R
- https://www.{BLOCKED}e.com/playlist?list=PLMaq39BTAz-KwwAqvQL33f_Y56Mplr5_7
- https://{BLOCKED}l.vn/thong-tin-lien-he/
- https://sites.{BLOCKED}e.com/view/nguyengiangvtv/HuongDan/HuongdankhaibaoTKguithu
- https://myaccount.{BLOCKED}e.com/security
- https://www.{BLOCKED}e.com/search?q=bat+pop+va+imap+cho+tai+khoan+gmail
- https://{BLOCKED}html.net/
It does the following:
- Executes its routines only after the user enables macros and interacts with the form embedded in the workbook, since it does not run any routine when the workbook is merely opened.
- Sends mail messages in a loop without prompting the user for confirmation for each message, and marks each message as high importance.
- Attaches up to four files per mail message, taken from the exported document file and from file names read from worksheet cells.
- Exports worksheets as document files into %User Profile%\Documents, or into C:\1 temp when the documents folder cannot be resolved.
- Renders worksheet ranges into an HTML file in %User Temp%, reads the file back, and deletes it afterwards.
- Creates a worksheet named Tempvtv1 and sets it to a very hidden state, which prevents it from being displayed through the normal spreadsheet interface.
- Executes a command taken from the registry entry HKEY_CURRENT_USER\Software\VB and VBA Program Settings\liliiliiliiiliilli\liliiliiliiili\ChonOutlook without validating its contents, allowing any command written to that entry to be run under the context of the affected user.
- Suppresses the following while its routines run:
- application alerts
- event handling
- screen updating
- link update prompts
(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name} on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).. %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000(32-bit), XP, and Server 2003(32-bit), or C:\Users\{user name}\AppData\Local\Temp on Windows Vista, 7, 8, 8.1, 2008(64-bit), 2012(64-bit) and 10(64-bit).)
SOLUTION
Step 1
Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.
Step 2
Note that not all files, folders, and registry keys and entries are installed on your computer during this malware's/spyware's/grayware's execution. This may be due to incomplete installation or other operating system conditions. If you do not find the same files/folders/registry information, please proceed to the next step.
Step 3
Delete this registry key
Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.
- In HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
- liliiliiliiiliilli
- liliiliiliiiliilli
- In HKEY_CURRENT_USER\Software\VB and VBA Program Settings\
- liliiliiliiiliill
- liliiliiliiiliill
Step 4
Search and delete this file
- %User Temp%\{dd-mm-yy h-mm-ss}.htm
- %User Profile%\Documents\{number} PDF.pdf
- %System Root%\1 temp\{number} PDF.pdf
Step 5
Search and delete this folder
- %System Root%\1 temp
Step 6
Scan your computer with your Trend Micro product to delete files detected as Trojan.X97M.INFOSTEAL.C. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information:
Did this description help? Tell us how we did.


