{"id":84137,"date":"2017-04-14T10:15:19","date_gmt":"2017-04-14T04:45:19","guid":{"rendered":"https:\/\/blogs_admin.quickheal.com\/?p=84137"},"modified":"2017-04-14T11:07:47","modified_gmt":"2017-04-14T05:37:47","slug":"cerber-ransomware-kovter-trojan-team-together","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/cerber-ransomware-kovter-trojan-team-together\/","title":{"rendered":"Cerber Ransomware and Kovter Trojan Team up Together"},"content":{"rendered":"<p>For the last 2 weeks, we have been observing a malware campaign using spam emails that look like they are from United States Postal Service (USPS) or FedEx. These emails are distributing the Cerber Ransomware along with Kovter Trojan &#8211; a lethal combination!<\/p>\n<p>The spam email contains a malicious script file linked to compromised websites from where additional components can be downloaded. We have come across about 300 such websites used in this malware campaign that are hacked and compromised by attackers.<\/p>\n<p><strong>How the attack works<br \/>\n<\/strong>The victim first opens the email attachment containing a <strong>script file<\/strong> expecting it to be the document mentioned in the received email.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-84131\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter1.png\" alt=\"cerber-and-kovter1\" width=\"741\" height=\"536\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter1.png 1155w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter1-300x217.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter1-768x555.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter1-539x390.png 539w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter1-789x570.png 789w\" sizes=\"(max-width: 741px) 100vw, 741px\" \/><\/p>\n<p style=\"text-align: center\">Fig 1. Malicious script file<\/p>\n<p>The script gets executed by Window\u2019s Wscript and connects to one of the compromised websites for downloading a \u2018counter.js\u2019 file which gets executed from the temp directory itself. The counter.js file then downloads another doc file which is responsible for downloading the Cerber Ransomware payload. The payload is dropped in Windows temp directory (%temp%) from where it gets executed and starts encrypting the victim\u2019s files.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-84132\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter2.png\" alt=\"Cerber ransom note\" width=\"782\" height=\"451\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter2.png 857w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter2-300x173.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter2-768x443.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter2-650x375.png 650w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter2-789x455.png 789w\" sizes=\"(max-width: 782px) 100vw, 782px\" \/><\/p>\n<p style=\"text-align: center\">Fig 2. Ransom note of Cerber Ransomware<\/p>\n<p>Cerber encrypt the user\u2019s data with a random name extension and demands a ransom in exchange for a key that can decrypt the data.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-84133\" src=\"https:\/\/blogs_admin.quickheal.com\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter3.png\" alt=\"cerber-and-kovter3\" width=\"767\" height=\"529\" srcset=\"https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter3.png 861w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter3-300x207.png 300w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter3-768x530.png 768w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter3-565x390.png 565w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter3-789x544.png 789w, https:\/\/www.quickheal.com\/blogs\/wp-content\/uploads\/2017\/04\/Cerber-and-Kovter3-229x158.png 229w\" sizes=\"(max-width: 767px) 100vw, 767px\" \/><\/p>\n<p style=\"text-align: center\">Fig 3. Files encrypted by Cerber with random characters<\/p>\n<p>The attack, however, does not stop at data encryption. The <strong>script file <\/strong>(mentioned earlier) then proceeds to install the Kovter fileless malware that hides in Windows Registry making its presence undetectable. Like other Trojans, Kovter gathers the user\u2019s data and sends it to its Command &amp; Control server (CnC) which is controlled by the attacker. Kovter is also used for click fraud campaigns where a computer or a person is maliciously used to click on online ads to generate revenue.<\/p>\n<p>Read more about Koveter in our blog post: <a href=\"https:\/\/blogs.quickheal.com\/kovter-the-fileless-click-fraud-malware\/\" target=\"_blank\">Kovter: the fileless click fraud malware <\/a><\/p>\n<p><strong>Quick Heal Detection<\/strong><\/p>\n<ol>\n<li>Quick Heal Email Protection feature successfully blocks such malicious attachments (the script file, in this case) even before they are executed.<\/li>\n<li>Quick Heal Web Security feature successfully blocks the malicious websites linked to these attachments.<\/li>\n<\/ol>\n<p><strong>Precautionary Measures<\/strong><\/p>\n<ol>\n<li>Never open email attachments with double extensions such as .doc.js and doc.vbs &#8211; these are most likely to contain malware. Set \u2018systems folder\u2019 options to show extensions for known file types, to identify such files.<\/li>\n<li>Never download attachments or click on links in emails received from unknown, unwanted or unexpected sources.<\/li>\n<li>Don\u2019t respond to pop-up notifications or alerts while visiting unfamiliar websites.<\/li>\n<li>Apply all recommended security updates to your OS, software, and Internet browsers, if not already.<\/li>\n<li>Have an <a href=\"https:\/\/www.quickheal.co.in\/home-users\/quick-heal-total-security\">antivirus software<\/a> installed on your computer that efficiently blocks spam and malicious emails, and automatically restricts access to malicious websites.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><strong>Acknowledgment<\/strong><\/p>\n<ul>\n<li>Prashant Tilekar<br \/>\nThreat Research and Response Team<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>For the last 2 weeks, we have been observing a malware campaign using spam emails that look like they are from United States Postal Service (USPS) or FedEx. These emails are distributing the Cerber Ransomware along with Kovter Trojan &#8211; a lethal combination! The spam email contains a malicious script file linked to compromised websites [&hellip;]<\/p>\n","protected":false},"author":29,"featured_media":84139,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24,910],"tags":[1139,1428,1429],"class_list":["post-84137","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-ransomware","tag-banking-trojan","tag-cerber-ransomware","tag-kovter-trojan"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/84137"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=84137"}],"version-history":[{"count":4,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/84137\/revisions"}],"predecessor-version":[{"id":84142,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/84137\/revisions\/84142"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media\/84139"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=84137"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=84137"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=84137"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}