From 94fa3c86b88589b377144d3e51a4169032df69a0 Mon Sep 17 00:00:00 2001 From: Lauren Parker <72159501+lparker31@users.noreply.github.com> Date: Wed, 1 Mar 2023 03:12:22 -0500 Subject: [PATCH] Lauren malware corpus (#81) * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated info * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * updated ID number * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos * fixed typos --- anti-behavioral-analysis/capture-evasion.md | 22 ++- .../debugger-detection.md | 37 +++-- anti-behavioral-analysis/debugger-evasion.md | 12 +- .../dynamic-analysis-evasion.md | 11 +- .../emulator-detection.md | 7 + anti-behavioral-analysis/emulator-evasion.md | 2 +- .../memory-dump-evasion.md | 1 + anti-behavioral-analysis/sandbox-detection.md | 33 ++++- .../virtual-machine-detection.md | 42 ++++-- anti-static-analysis/disassembler-evasion.md | 6 +- .../executable-code-obfuscation.md | 25 +++- .../executable-code-virtualization.md | 2 +- anti-static-analysis/software-packing.md | 19 +-- collection/input-capture.md | 9 +- collection/keylogging.md | 26 ++-- collection/screen-capture.md | 15 +- command-and-control/c2-communication.md | 66 +++++---- command-and-control/domain-name-generation.md | 12 +- command-and-control/ingress-tool-transfer.md | 36 +++-- .../alternative-installation-location.md | 7 +- defense-evasion/bootkit.md | 5 +- .../disable-or-evade-security-tools.md | 11 +- .../hidden-files-and-directories.md | 13 +- defense-evasion/hide-artifacts.md | 4 +- defense-evasion/hijack-execution-flow.md | 14 +- defense-evasion/indicator-blocking.md | 9 +- ...all-insecure-or-malicious-configuration.md | 6 +- defense-evasion/modify-registry.md | 17 ++- .../obfuscated-files-or-information.md | 63 ++++---- defense-evasion/polymorphic-code.md | 4 +- defense-evasion/process-injection.md | 46 +++--- defense-evasion/rootkit.md | 18 ++- defense-evasion/self-deletion.md | 12 +- discovery/analysis-tool-discovery.md | 22 ++- discovery/application-window-discovery.md | 12 +- discovery/code-discovery.md | 22 +-- discovery/file-and-directory-discovery.md | 43 +++--- discovery/system-information-discovery.md | 43 +++--- discovery/taskbar-discovery.md | 2 +- .../command-and-scripting-interpreter.md | 37 ++--- execution/conditional-execution.md | 30 ++-- execution/execution-dependency.md | 2 +- .../exploitation-for-client-execution.md | 4 +- execution/install-additional-program.md | 42 +++--- execution/remote-commands.md | 12 +- execution/send-email.md | 5 +- execution/user-execution.md | 15 +- exfiltration/archive-collected-data.md | 9 +- impact/clipboard-modification.md | 11 +- impact/data-destruction.md | 11 +- impact/data-encrypted-for-impact.md | 11 +- impact/denial-of-service.md | 4 +- impact/destroy-hardware.md | 2 +- impact/disk-wipe.md | 4 +- impact/exploit-kit.md | 8 + impact/generate-traffic-from-victim.md | 8 +- impact/manipulate-network-traffic.md | 8 +- impact/remote-access.md | 9 +- impact/resource-hijacking.md | 9 +- impact/spamming.md | 2 +- lateral-movement/supply-chain-compromise.md | 9 +- .../communication/dns-communication.md | 4 +- .../communication/http-communication.md | 13 +- .../interprocess-communication.md | 2 +- .../communication/smtp-communication.md | 2 +- .../communication/socket-communication.md | 9 +- .../cryptography/cryptographic-hash.md | 11 +- micro-behaviors/cryptography/decrypt-data.md | 2 +- micro-behaviors/cryptography/encrypt-data.md | 34 +++-- .../cryptography/encryption-key.md | 11 +- .../generate-pseudorandom-sequence.md | 4 +- micro-behaviors/data/check-string.md | 7 +- micro-behaviors/data/checksum.md | 11 +- micro-behaviors/data/compression-library.md | 2 +- micro-behaviors/data/decode-data.md | 4 +- micro-behaviors/data/decompress-data.md | 2 +- micro-behaviors/data/encode-data.md | 32 ++-- micro-behaviors/data/use-constant.md | 2 +- micro-behaviors/file-system/copy-file.md | 12 +- .../file-system/create-directory.md | 14 +- .../file-system/delete-directory.md | 2 +- micro-behaviors/file-system/delete-file.md | 26 ++-- .../file-system/get-file-attributes.md | 12 +- micro-behaviors/file-system/move-file.md | 12 +- micro-behaviors/file-system/read-file.md | 28 ++-- .../file-system/set-file-attributes.md | 12 +- micro-behaviors/file-system/writes-file.md | 24 +-- micro-behaviors/memory/allocate-memory.md | 18 +-- .../memory/change-memory-protection.md | 7 +- micro-behaviors/memory/overflow-buffer.md | 2 +- .../operating-system/environment-variable.md | 4 +- micro-behaviors/operating-system/registry.md | 47 ++++-- .../process/allocate-thread-local-storage.md | 4 +- micro-behaviors/process/check-mutex.md | 6 +- micro-behaviors/process/create-mutex.md | 16 +- micro-behaviors/process/create-process.md | 27 ++-- micro-behaviors/process/create-thread.md | 12 +- micro-behaviors/process/resume-thread.md | 4 +- .../process/set-thread-local-storage-value.md | 12 +- micro-behaviors/process/suspend-thread.md | 8 +- micro-behaviors/process/terminate-process.md | 18 +-- persistence/component-firmware.md | 7 +- persistence/malicious-network-driver.md | 3 +- persistence/modify-existing-service.md | 11 +- .../registry-run-keys-startup-folder.md | 42 +++--- privilege-escalation/install-certificate.md | 2 +- xample-malware/README.md | 75 +++++----- xample-malware/bagle.md | 11 +- xample-malware/blackenergy.md | 62 ++++---- xample-malware/chopstick.md | 16 +- xample-malware/clipminer.md | 20 +-- xample-malware/conficker.md | 21 +-- xample-malware/cozycar.md | 11 +- xample-malware/cryptolocker.md | 45 +++--- xample-malware/cryptowall.md | 22 +-- xample-malware/dark-comet.md | 96 ++++++------ xample-malware/dnschanger.md | 36 ++--- xample-malware/emotet.md | 32 ++-- xample-malware/evilbunny.md | 12 +- xample-malware/gamut.md | 73 ++++----- xample-malware/geneio.md | 9 +- xample-malware/gobotkr.md | 86 +++++------ xample-malware/gravity-rat.md | 38 ++--- xample-malware/heriplor.md | 12 +- xample-malware/hupigon.md | 139 +++++++++--------- xample-malware/kovter.md | 89 +++++------ xample-malware/kraken.md | 21 +-- xample-malware/locky-bart.md | 44 +++--- xample-malware/matanbuchus.md | 81 ++++++++++ xample-malware/mazarbot.md | 14 +- xample-malware/mebromi.md | 45 +++--- xample-malware/netwalker.md | 11 +- xample-malware/poison-ivy.md | 47 +++--- xample-malware/rebhip.md | 99 ------------- xample-malware/redhip.md | 100 +++++++++++++ xample-malware/rombertik.md | 104 ++++++------- xample-malware/samsam.md | 23 +-- xample-malware/searchawesome.md | 18 +-- xample-malware/shamoon.md | 70 ++++----- xample-malware/stuxnet.md | 52 ++++--- xample-malware/synful-knock.md | 19 +-- xample-malware/teardrop.md | 59 ++++++++ xample-malware/terminator.md | 19 ++- xample-malware/trickbot.md | 52 ++++--- xample-malware/up007.md | 86 +++++------ xample-malware/ursnif.md | 42 +++--- xample-malware/vobfus.md | 83 +++++++++++ xample-malware/webcobra.md | 41 +++--- xample-malware/yispecter.md | 21 +-- 149 files changed, 2089 insertions(+), 1519 deletions(-) create mode 100644 xample-malware/matanbuchus.md delete mode 100644 xample-malware/rebhip.md create mode 100644 xample-malware/redhip.md create mode 100644 xample-malware/teardrop.md create mode 100644 xample-malware/vobfus.md diff --git a/anti-behavioral-analysis/capture-evasion.md b/anti-behavioral-analysis/capture-evasion.md index e4306bb..2fe3bab 100644 --- a/anti-behavioral-analysis/capture-evasion.md +++ b/anti-behavioral-analysis/capture-evasion.md @@ -38,6 +38,26 @@ Malware has characteristics enabling it to evade capture from the infected syste |Name|ID|Description| |---|---|---| -|**Encrypted Payloads**|B0036.002|Decryption key is stored external to the executable or never touches the disk.| +|**Encrypted Payloads**|B0036.002|The decryption key is stored external to the executable or never touches the disk.| |**Memory-only Payload**|B0036.001|Malware is never written to disk (e.g., RAT plugins received from the controller are never written to disk).| |**Multiple Stages of Loaders**|B0036.003|Multiple stages of loaders are used with an encoded payload.| + +## Use in Malware + +|Name|Date|Method|Description| +|---|---|---|---| +|[**Vobfus**](../xample-malware/vobfus.md)|2016|B0036.002|Vobfus is downloaded in an encrypted form then decrypted. [[1]](#1)| +|[**TEARDROP**](../xample-malware/teardrop.md)|2018|B0036.001|TEARDROP loads its payload only into memory. [[2]](#2)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0036.001|The malware downloads multiple payloads (as files and DLLs) that are stored in a memory buffer. [[4]](#4)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0036.003|Matanbuchus consists of 2 loaders. [[3]](#3) [[4]](#4)| + + +## References + +[1] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ + +[2] https://www.cisa.gov/uscert/ncas/analysis-reports/ar21-039b + +[3] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ + +[4] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader \ No newline at end of file diff --git a/anti-behavioral-analysis/debugger-detection.md b/anti-behavioral-analysis/debugger-detection.md index 07be2c5..d0a3210 100644 --- a/anti-behavioral-analysis/debugger-detection.md +++ b/anti-behavioral-analysis/debugger-detection.md @@ -47,7 +47,7 @@ Details on methods of detecting debuggers are given in the references; many are |**CloseHandle**|B0001.003|(NtClose); If an invalid handle is passed to the CloseHandle function and a debugger is present, then an EXCEPTION_INVALID_HANDLE (0xC0000008) exception will be raised. [[7]](#7)| |**Debugger Artifacts**|B0001.004|Malware may detect a debugger by its artifact (window title, device driver, exports, etc.).| |**Hardware Breakpoints**|B0001.005|(SEH/GetThreadContext); Debug registers will indicate the presence of a debugger. See [[7]](#7) for details.| -|**Interruption**|B0001.006|If an interruption is mishandled by the debugger, it can cause a single-byte instruction to be inadvertently skipped, which can be detected by malware. Examples include Interrupt 0x2d and Interrupt 1 [7].| +|**Interruption**|B0001.006|If an interruption is mishandled by the debugger, it can cause a single-byte instruction to be inadvertently skipped, which can be detected by malware. Examples include Interrupt 0x2d and Interrupt 1 [[7]](#7).| |**IsDebuggerPresent**|B0001.008|The kernel32!IsDebuggerPresent API function call checks the PEB BeingDebugged flag to see if the calling process is being debugged. It returns 1 if the process is being debugged, 0 otherwise. This is one of the most common ways of debugger detection.| |**Memory Breakpoints**|B0001.009|(PAGE_GUARD); Guard pages trigger an exception the first time they are accessed and can be used to detect a debugger. See [[7]](#7) for details.| |**Memory Write Watching**|B0001.010|[[7]](#7)| @@ -82,14 +82,24 @@ Details on methods of detecting debuggers are given in the references; many are |Name|Date|Method|Description| |---|---|---|---| -|[**Redhip**](../xample-malware/rebhip.md)|January 2011|B0001, B0001.035, B0001.032|Please see the Redhip malware page for details. [[4]](#4)| -|[**Gamut**](../xample-malware/gamut.md)|2014|B0001.006, B0001.008|Please see the Gamut malware page for details. [[8]](#8)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0001.016, B0001.038, B0001.032|Please see the Rombertik malware page for details. [[9]](#9)| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|B0001.005, B0001.008|Please see the Poison-Ivy malware page for details. [[10]](#10)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|B0001.032|Check for time delay via GetTickCount (This capa rule had 4 matches) [[11]](#11)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0001.034, B0001.025, B0001.032|Please see the Hupigon malware page for details. [[11]](#11)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|B0001.032|Check for time delay via GetTickCount (This capa rule had 1 match) [[11]](#11)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0001.028|Manipulates TLS Callbacks while injecting to child process [[12]](#12)| +|[**Redhip**](../xample-malware/redhip.md)|2011|--|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFTICE. [[4]](#4)| +|[**Redhip**](../xample-malware/redhip.md)|2011|B0001.032|Redhip checks for a time delay using GetTickCount. [[15]](#15)| +|[**Redhip**](../xample-malware/redhip.md)|2011|B0001.035|Redhip checks for PEB BeingDebugged flag. [[15]](#15)| +|[**Gamut**](../xample-malware/gamut.md)|2014|B0001.006|The malware detects debuggers using an INT 03h trap. [[8]](#8)| +|[**Gamut**](../xample-malware/gamut.md)|2014|B0001.008|The malware detects debuggers using IsDebuggerPresent. [[8]](#8)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0001.016|The malware calls the Windows API OutputDebugString function 335,000 times. [[9]](#9)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0001.032|The malware checks for a time delay via GetTickCount. [[15]](#15)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0001.038|An anti-analysis function within the packer is called to check the username and filename of the executing process for strings like “malwar”, “sampl”, “viru”, and “sandb”. [[9]](#9)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|B0001.005|Poison Ivy Variant checks for breakpoints and exits immediately if found. [[13]](#13)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|B0001.008|Poison Ivy uses the IsDebuggerPresent API function call to check if the process is running in a debugger. [[13]](#13)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0001.032|The malware calls GetTickCount64 to retrieve timestamp. Malware executes Sleep and Beep in a repeated loop for 10 times. [[11]](#11) [[12]](#12)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0001.028|The malware manipulates TLS Callbacks while injecting to a child process. [[12]](#12)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|B0001.032|The malware checks for a time delay via GetTickCount. [[15]](#15)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0001.025|The malware checks for software breakpoints. [[15]](#15)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0001.032|The malware checks for a time delay via GetTickCount. [[15]](#15)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0001.034|The malware executes anti-debugging instructions. [[15]](#15)| +|[**UP007**](../xample-malware/up007.md)|2016|B0001.032|The malware checks for a time delay via GetTickCount. [[15]](#15)| + ## References @@ -113,7 +123,12 @@ Details on methods of detecting debuggers are given in the references; many are [10] https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf -[11] capa v4.0, analyzed at MITRE on 10/12/2022 +[11] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ -[12] https://www.fireeye.com/blog/threat-research/2017/11/ursnif-variant-malicious-tls-callback-technique.html +[12] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader +[13] https://www.fortinet.com/blog/threat-research/deep-analysis-of-new-poison-ivy-variant + +[14] https://www.fireeye.com/blog/threat-research/2017/11/ursnif-variant-malicious-tls-callback-technique.html + +[15] capa v4.0, analyzed at MITRE on 10/12/2022 diff --git a/anti-behavioral-analysis/debugger-evasion.md b/anti-behavioral-analysis/debugger-evasion.md index b39a4e8..aa98c68 100644 --- a/anti-behavioral-analysis/debugger-evasion.md +++ b/anti-behavioral-analysis/debugger-evasion.md @@ -45,7 +45,7 @@ The related **Debugger Evasion ([T1622](https://attack.mitre.org/techniques/T162 |**Block Interrupts**|B0002.001|Block interrupt (via hooking) 1 and/or 3 to prevent debuggers from working.| |**Break Point Clearing**|B0002.002|Intentionally clearing software or hardware breakpoints.| |**Byte Stealing**|B0002.003|Move or copy the first bytes / instructions of the original code elsewhere. AKA stolen bytes or code splicing. For example, a packer may incorporate the first few instructions of the original EntryPoint (EP) into its unpacking stub before the tail transition in order to confuse automated unpackers and novice analysts. This can make it harder for rebuilding and may bypass breakpoints if set prematurely.| -|**Change SizeOfImage**|B0002.004|Changing this value during run time can prevent some debuggers from attaching. Also confuses some unpackers and dumpers.| +|**Change SizeOfImage**|B0002.004|Changing this value during run time can prevent some debuggers from attaching and also confuses some unpackers and dumpers.| |**Code Integrity Check**|B0002.005|Check that the unpacking code is unmodified. Variation exists where unpacking code is part of the "key" used to unpack, therefore any Software Breakpoints during debugging causes unpacking to completely fail or result in malformed unpacked code.| |**Exception Misdirection**|B0002.006|Using exception handling (SEH) to cause flow of program to non-obvious paths.| |**Get Base Indirectly**|B0002.007|CALL to a POP; finds base of code or data, often the packed version of the code; also used often in obfuscated/packed shellcode.| @@ -77,8 +77,11 @@ The related **Debugger Evasion ([T1622](https://attack.mitre.org/techniques/T162 |Name|Date|Method|Description| |---|---|---|---| -|**Fake Adobe Flash Update OS X**|February 2016|--|Malware contains code that manually detects a debugger [[2]](#2)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFICE. [[3]](#3)| +|**Fake Adobe Flash Update OS X**|2016|--|Malware contains code that manually detects a debugger. [[2]](#2)| +|**Dridex**|2015|--|[[3]](#3)| +|[**Redhip**](../xample-malware/redhip.md)|2011|--|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFTICE. [[6]](#6)| +|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Vobfus uses GetModuleHandle API to check for the presence of a debugger. [[7]](#7)| + ## References @@ -86,7 +89,7 @@ The related **Debugger Evasion ([T1622](https://attack.mitre.org/techniques/T162 [2] https://www.synack.com/2016/02/17/analyzing-the-anti-analysis-logic-of-an-adware-installer/ -[3] https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html +[3] http://phishme.com/dridex-code-breaking-modify-the-malware-to-bypass-the-vm-bypass/ [4] http://antukh.com/blog/2015/01/19/malware-techniques-cheat-sheet/ @@ -94,3 +97,4 @@ The related **Debugger Evasion ([T1622](https://attack.mitre.org/techniques/T162 [6] https://web.archive.org/web/20161025013916/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html +[7] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ diff --git a/anti-behavioral-analysis/dynamic-analysis-evasion.md b/anti-behavioral-analysis/dynamic-analysis-evasion.md index b2d3939..59fe8b5 100644 --- a/anti-behavioral-analysis/dynamic-analysis-evasion.md +++ b/anti-behavioral-analysis/dynamic-analysis-evasion.md @@ -60,12 +60,14 @@ The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/t |Name|Date|Method|Description| |---|---|---|---| -|[**Terminator**](../xample-malware/terminator.md)|October 2013|B0003.003|The Terminator rat evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[3]](#3)| +|[**Terminator**](../xample-malware/terminator.md)|2013|B0003.003|The Terminator RAT evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[3]](#3)| |**Nap**|2013|--|Trojan Nap (tied to the Kelihos Botnet) uses extended sleep calls to evade sandbox analysis. [[3]](#3)| |**Smokeloader**|2019|--|Smokeloader drops a copy of ntdll.dll to %APPDATA%\Local\Temp\ [[4]](#4)| -|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|Evades dynamic analysis. [[2]](#2)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0003.002, B0003.011|Please see the Rombertik malware page for details. [[5]](#5)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|B0003.012|Uses numerous printf loops to delay the execution process and overload the sandbox with junk data (API Hammering) [[6]](#6)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|B0003.001|The malware loads ntdll.dll and user32.dll as data files and overwrites the first 8 bytes of those functions to avoid API hooking by security products. [[7]](#7)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0003.002|The malware stalls by writing a byte of random data to memory 960 million times which complicates analysis. It also calls specific Windows API functions. [[5]](#5)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0003.011|The malware computes a 32-bit hash of a resource in memory, and compares it to the PE Compile Timestamp of the unpacked sample. If the resource or compile time has been altered, the malware acts destructively. [[5]](#5)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|B0003.012|The malware uses numerous printf loops to delay the execution process and overload the sandbox with junk data (API Hammering). [[6]](#6)| + ## References @@ -80,4 +82,3 @@ The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/t [5] https://blogs.cisco.com/security/talos/rombertik [6] https://www.joesecurity.org/blog/498839998833561473 - diff --git a/anti-behavioral-analysis/emulator-detection.md b/anti-behavioral-analysis/emulator-detection.md index 14637e5..b0717f1 100644 --- a/anti-behavioral-analysis/emulator-detection.md +++ b/anti-behavioral-analysis/emulator-detection.md @@ -49,6 +49,13 @@ Detects whether the malware instance is being executed inside an emulator. If so |---|---|---| |[check if process is running under wine](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-emulation/wine/check-if-process-is-running-under-wine.yml)|Emulator Detection (B0007)|GetModuleHandle, GetProcAddress| + +## Use in Malware + +|Name|Date|Method|Description| +|---|---|---|---| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Stuxnet checks for specific operating systems on 32-bit machines, registry keys, and dates to profile a potential target machine before execution. If the conditions are not met to be considered a viable target, it will exit execution. [[2]](#2)| + ## References [1] https://search.unprotect.it/map/sandbox-evasion/ diff --git a/anti-behavioral-analysis/emulator-evasion.md b/anti-behavioral-analysis/emulator-evasion.md index 8200094..28db62b 100644 --- a/anti-behavioral-analysis/emulator-evasion.md +++ b/anti-behavioral-analysis/emulator-evasion.md @@ -43,7 +43,7 @@ Behaviors that obstruct analysis in an emulator. |Name|Date|Method|Description| |---|---|---|---| -|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|Evades emulator-based analysis. [[1]](#1)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|B0005.004|The malware evades emulator-based analysis by using an infinite loop to check all open windows and compare each window's title bar to a list of strings. [[1]](#1)| ## References diff --git a/anti-behavioral-analysis/memory-dump-evasion.md b/anti-behavioral-analysis/memory-dump-evasion.md index c54b809..ced3305 100644 --- a/anti-behavioral-analysis/memory-dump-evasion.md +++ b/anti-behavioral-analysis/memory-dump-evasion.md @@ -55,6 +55,7 @@ Malware hinders retrieval and/or discovery of the contents of the physical memor |---|---|---|---| |[**Kraken**](../xample-malware/kraken.md)|2008|--|Dumping Kraken's c.dll module from the heap of its own process is tricky because its PE-header is erased in memory. [[2]](#2)| + ## Code Snippets ### B0006.011 diff --git a/anti-behavioral-analysis/sandbox-detection.md b/anti-behavioral-analysis/sandbox-detection.md index f6f870e..02063ac 100644 --- a/anti-behavioral-analysis/sandbox-detection.md +++ b/anti-behavioral-analysis/sandbox-detection.md @@ -55,11 +55,27 @@ The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/t |Name|Date|Method|Description| |---|---|---|---| -|[**Redhip**](../xample-malware/rebhip.md)|2011|B0007.005|Redhip detects publicly available automated analysis workbenches (e.g., Joe Box) by considering OS product keys and special DLLs. [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0007.010|The malware check for sandboxes that suppress errors returned from API routine calls the using ZwGetWriteWatch routine. [[2]](#2)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0007.007|Ursnif uses malware macros to evade sandbox detection. [[6]](#6)| -|[**EvilBunny**](../xample-malware/evilbunny.md)|2011|--|EvilBunny hooks time retrieval APIs and calls each API twice to calculate a delta. Execution aborts depending on the delta value [[4]](#4)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR performs several checks on the compromised machine to avoid being emulated or executed in a sandbox. [[5]](#5)| +|[**Redhip**](../xample-malware/redhip.md)|2011|B0007.005|Redhip detects publicly available automated analysis workbenches (e.g., Joe Box) by considering OS product keys and special DLLs and checks for sandboxes and AV modules. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0007.010|The malware checks for sandboxes that suppress errors returned from API routine calls the using ZwGetWriteWatch routine. [[2]](#2)| +|[**Terminator**](../xample-malware/terminator.md)|2013|--|The Terminator RAT evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[4]](#4)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0007.007|Ursnif uses malware macros to evade sandbox detection - checking whether the filename contains only hexadecimal characters before the extension. [[8]](#8)| +|[**GotBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR performs several checks on the compromised machine to avoid being emulated or executed in a sandbox. [[5]](#5)| +|[**EvilBunny**](../xample-malware/evilbunny.md)|2011|--|EvilBunny hooks time retrieval APIs and calls each API twice to calculate a delta. Execution aborts depending on the delta value. [[6]](#6)| +|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Vobfus uses GetModuleHandle API to check for the presence of a sandbox. [[7]](#7)| + + +## Detection + +|Tool: capa|Mapping|APIs| +|---|---|---| +|[check for microsoft office emulation](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-vm/vm-detection/check-for-microsoft-office-emulation.yml)|Sandbox Detection::Product Key/ID Testing (B0007.005)|CreateFile| +|[check for sandbox and av modules](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-av/check-for-sandbox-and-av-modules.yml)|Sandbox Detection (B0007)|GetModuleHandle| + +|Tool: CAPE|Mapping|APIs| +|---|---|---| +|[antisandbox_joe_anubis_files.py](https://github.com/kevoreilly/community/blob/master/modules/signatures/antisandbox_joe_anubis_files.py)|Sandbox Detection::Check Files (B0007.002)|--| +|[antisandbox_cuckoo_files](https://github.com/kevoreilly/community/blob/master/modules/signatures/antisandbox_cuckoo_files.py)|Sandbox Detection::Check Files (B0007.002)|--| + ## Code Snippets @@ -105,9 +121,12 @@ mov bl, 1 [3] https://github.com/LordNoteworthy/al-khaser -[4] https://web.archive.org/web/20150311013500/http://www.cyphort.com/evilbunny-malware-instrumented-lua/ +[4] https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/pf/file/fireeye-hot-knives-through-butter.pdf [5] https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/ -[6] https://www.proofpoint.com/us/threat-insight/post/ursnif-banking-trojan-campaign-sandbox-evasion-techniques +[6] https://web.archive.org/web/20150311013500/http://www.cyphort.com/evilbunny-malware-instrumented-lua/ +[7] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ + +[8] https://www.proofpoint.com/us/threat-insight/post/ursnif-banking-trojan-campaign-sandbox-evasion-techniques diff --git a/anti-behavioral-analysis/virtual-machine-detection.md b/anti-behavioral-analysis/virtual-machine-detection.md index 0b5d587..7c94074 100644 --- a/anti-behavioral-analysis/virtual-machine-detection.md +++ b/anti-behavioral-analysis/virtual-machine-detection.md @@ -43,8 +43,8 @@ The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/t |**Check File and Directory Artifacts**|B0009.001|Virtual machines create files on the file system (e.g., VMware creates files in the installation directory C:\Program Files\VMware\VMware Tools). Malware can check the different folders to find virtual machine artifacts (e.g., Virtualbox has the artifact VBoxMouse.sys). [[2]](#2)| |**Check Memory Artifacts**|B0009.002|VMware leaves many artifacts in memory. Some are critical processor structures, which, because they are either moved or changed on a virtual machine, leave recognizable footprints. Malware can search through physical memory for the strings VMware, commonly used to detect memory artifacts. [[2]](#2)| |**Check Named System Objects**|B0009.003|Virtual machines often include specific named system objects by default, such as Windows device drivers, which can be detected by testing for specific strings, whether found in the Windows registry or other places.| -|**Check Processes**|B0009.004|The VMware Tools use processes like VMwareServices.exe or VMwareTray.exe, to perform actions on the virtual environment. Malware can list the process and searches for the VMware string. Process related to Virtualbox can be detected by malware by query the process list. [[2]](#2)| -|**Check Registry Keys**|B0009.005|Virtual machines register artifacts in the registry, which can be detected by malware. For example, a search for "VMware" or "VBOX" in the registry might reveal keys that include information about a virtual hard drive, adapters, running services, or virtual mouse. [[2]](#2) Example registry key value artifacts include "HARDWARE\Description\System (SystemBiosVersion) (VBOX)" and "SYSTEM\ControlSet001\Control\SystemInformation (SystemManufacturer) (VMWARE)"; example registry key artifacts include "SOFTWARE\VMware, Inc.\VMware Tools (VMWARE)" and "SOFTWARE\Oracle\VirtualBox Guest Additions (VBOX)". [[5]](#5)| +|**Check Processes**|B0009.004|The VMware Tools use processes like VMwareServices.exe or VMwareTray.exe, to perform actions on the virtual environment. Malware can list the processes and searches for the VMware string. Processes related to Virtualbox can be detected by the malware by querying the process list. [[2]](#2)| +|**Check Registry Keys**|B0009.005|Virtual machines register artifacts in the registry, which can be detected by malware. For example, a search for "VMware" or "VBOX" in the registry might reveal keys that include information about a virtual hard drive, adapters, running services, or a virtual mouse. [[2]](#2) Example registry key value artifacts include "HARDWARE\Description\System (SystemBiosVersion) (VBOX)" and "SYSTEM\ControlSet001\Control\SystemInformation (SystemManufacturer) (VMWARE)"; example registry key artifacts include "SOFTWARE\VMware, Inc.\VMware Tools (VMWARE)" and "SOFTWARE\Oracle\VirtualBox Guest Additions (VBOX)". [[5]](#5)| |**Check Running Services**|B0009.006|VMwareService.exe runs the VMware Tools Service as a child of services.exe. It can be identified by listing services. [[2]](#2)| |**Check Software**|B0009.007|Malware may check software version; for example, to determine whether the software is relatively current.| |**Check Virtual Devices**|B0009.008|The presence of virtual devices can indicate a virtualized environment (e.g., "\\.\VBoxTrayIPC"). [[5]](#5)| @@ -84,13 +84,26 @@ The related **Virtualization/Sandbox Evasion ([T1497](https://attack.mitre.org/t |Name|Date|Method|Description| |---|---|---|---| -|[**GravityRAT**](../xample-malware/gravity-rat.md)|May 2018|B0009, B0009.024, B0009.023, B0009.018, B0009.028|Please see the GravityRAT malware page for details. [[3]](#3)| -|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|WebCobra injects malicious code to svchost.exe and uses an infinite loop to check all open windows and to compare each window’s title bar text with a set of strings to determine whether it is running in an isolated, malware analysis environment [[4]](#4)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip detects VMWare, Virtual PC and Virtual Box. It also detects VM environments in general by considering timing lapses. [[1]](#1)| -|[**Emotet**](../xample-malware/emotet.md)|2018|B0009.010|Emotet checks for various processes that are associated with various virtual machines by comparing hash values of the process names with the hash values of the list of running process names [[7]](#7)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|B0009.012|Check for unmoving mouse cursor (This capa rule had 1 match) [[8]](#8)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0009.004|Checks if there are virtual machine processes running (Vbox, vmware, etc) [[9]](#9)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0007.010, B0001.016, B0001.038|Please see the Rombertik malware page for details. [[10]](#10)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|GravityRAT checks system temperature by recording thermal readings for detecting VMs. Heat levels indicate whether the system is a VM. [[3]](#3)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|B0009.018|GravityRAT determines the machine is a VM if the core count is 1. [[3]](#3)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|B0009.023|GravityRAT checks if the manufacturer field in the Win32_Computer entry (in WMI) contains "Virtual," "Vmware," or "Virtualbox." [[3]](#3)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|B0009.024|GravityRAT creates a WMI request to identify the BIOS version. [[3]](#3)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|B0009.028|GravityRAT checks if the MAC address starts with a well-known hexadecimal number used by various VM developers. [[3]](#3)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|B0009.022|WebCobra injects malicious code in to svchost.exe and uses an infinite loop to check all open windows and to compare each window’s title bar text with a set of strings to determine whether it is running in a VM. [[4]](#4)| +|[**Redhip**](../xample-malware/redhip.md)|2011|--|Redhip detects VMWare, Virtual PC, and Virtual Box. It also detects VM environments in general by considering time lapses. [[6]](#6)| +|[**Emotet**](../xample-malware/emotet.md)|2018|B0009.010|Emotet checks for various processes that are associated with various virtual machines by comparing hash values of the process names with the hash values of the list of running process names. [[7]](#7)| +|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Vobfus checks for the presence of virtualization software by querying the system registry. [[8]](#8)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0009.003|Malware checks if it is running in a sandbox. If it is, the malware exits. [[9]](#9) [[10]](#10)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0009.004|The malware checks if there are virtual machine processes running (Vbox, vmware, etc). [[11]](#11)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|B0009.012|The malware checks for an unmoving mouse cursor. [[12]](#12)| + + +## Detection + +|Tool: capa|Mapping|APIs| +|---|---|---| +|[check if process is running under wine](https://github.com/mandiant/capa-rules/blob/master/anti-analysis/anti-emulation/wine/check-if-process-is-running-under-wine.yml)|Emulator Detection (B0007)|GetModuleHandle, GetProcAddress| + ## Code Snippets @@ -135,7 +148,7 @@ jmp short loc_401CBB ## References -[1] https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html +[1] https://web.archive.org/web/20161025013916/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html [2] https://search.unprotect.it/map/sandbox-evasion/ @@ -149,11 +162,12 @@ jmp short loc_401CBB [7] https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/ -[8] capa v4.0, analyzed at MITRE on 10/12/2022 +[8] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ -[9] https://www.proofpoint.com/us/threat-insight/post/ursnif-banking-trojan-campaign-sandbox-evasion-techniques +[9] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ -[10] https://blogs.cisco.com/security/talos/rombertik +[10] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader -[11] https://web.archive.org/web/20161025013916/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html +[11] https://www.proofpoint.com/us/threat-insight/post/ursnif-banking-trojan-campaign-sandbox-evasion-techniques +[12] capa v4.0, analyzed at MITRE on 10/12/2022 diff --git a/anti-static-analysis/disassembler-evasion.md b/anti-static-analysis/disassembler-evasion.md index 41c1b23..bf0cd14 100644 --- a/anti-static-analysis/disassembler-evasion.md +++ b/anti-static-analysis/disassembler-evasion.md @@ -48,9 +48,9 @@ Some methods apply to both types of disassemblers; others apply to one type and |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|B0012.001|Contain obfuscated stackstrings (This capa rule had 3 matches) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0012.001|Contain obfuscated stackstrings (This capa rule had 1 match) [[6]](#6)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0012.001|Contain obfuscated stackstrings (This capa rule had 1 match) [[6]](#6)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|B0012.001|BlackEnergy contains obfuscated stack strings. [[1]](#1) [[6]](#6)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0012.001|Hupigon contains obfuscated stack strings. [[6]](#6)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0012.001|Rombertik contains obfuscated stack strings. [[6]](#6)| ## References diff --git a/anti-static-analysis/executable-code-obfuscation.md b/anti-static-analysis/executable-code-obfuscation.md index b1c36d6..64ad71b 100644 --- a/anti-static-analysis/executable-code-obfuscation.md +++ b/anti-static-analysis/executable-code-obfuscation.md @@ -33,7 +33,7 @@ Executable code is obfuscated to hinder static code analysis. This behavior is specific to a malware sample's executable code (data and text sections). While the Executable Code Obfuscation behavior makes the analysis process more difficult, it does not cause incorrect or incomplete disassembly, which is how this behavior differs from the Disassembler Evasion behavior. -For encryption and encoding characteristics of malware samples, as well as malware obfuscation behaviors related to non-malware-sample files and information, see **Obfuscated Files or Information ([E1027](../defense-evasion/obfuscated-files-or-information.md))**. +For encryption and encoding characteristics of malware samples, as well as malware obfuscation behaviors related to non-malware sample files and information, see **Obfuscated Files or Information ([E1027](../defense-evasion/obfuscated-files-or-information.md))**. ## Methods @@ -65,8 +65,16 @@ For encryption and encoding characteristics of malware samples, as well as malwa |Name|Date|Method|Description| |---|---|---|---| +|[**Heriplor**](../xample-malware/heriplor.md)|2012|B0032.001|The Heriplor Trojan uses API Hashing. [[1]](#1)| |[**Emotet**](../xample-malware/emotet.md)|2018|B0032.007|Emotet macros are heavily obfuscated with junk functions and string substitutions. [[2]](#2)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0032.002|Most of the malware file consists of unnecessary code or unnecessary data [[1]](#1)| +|[**Rombertik**](../anti-static-analysis/executable-code-obfuscation.md)|2015|B0032.002|Most of the malware file consists of unnecessary code or unnecessary data. [[4]](#4)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|B0032.017|Poison Ivy variant encrypts all its strings. [[6]](#6)| +|[**SamSam**](../xample-malware/samsam.md)|2015|--|SamSam obfuscates functions, class names and strings, including the list of targeted file extensions, the help file contents and environment variables using DES encryption with a fixed hard-coded key and the IV. [[7]](#7)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1027.m01|The configuration data block is encoded with a NOT XOR 0xFF operation. [[8]](#8)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0032.001|The function to import APIs uses a hash value and the DLL name of the target API. The API address returned from the function is stored into a global variance. API calls are obfuscated in the same manner as the stack strings and are resolved dynamically as the malware needs to use them. The malware encodes data in a stack string and copies that data into a global character buffer as a form of string obfuscation. [[9]](#9) [[10]](#10)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0032.017|The malware encodes data in a stack string and copies that data into a global character buffer as a form of string obfuscation. Different techniques are used to encrypt and obfuscate strings. Strings are dynamically decrypted when the malware needs to use them. [[9]](#9) [[10]](#10)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0032.009|The malware has 4 different export functions. [[9]](#9) [[10]](#10)| + ## Code Snippets @@ -139,3 +147,16 @@ jmp short loc_401326 [3] Rob Simmons, "Comparing Malicious Files," BSides, 2019. http://www.irongeek.com/i.php?page=videos/bsidescharm2019/2-04-comparing-malicious-files-robert-simmons +[4] https://blogs.cisco.com/security/talos/rombertik + +[5] https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality + +[6] https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf + +[7] https://blog.talosintelligence.com/2018/01/samsam-evolution-continues-netting-over.html + +[8] https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en + +[9] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ + +[10] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader diff --git a/anti-static-analysis/executable-code-virtualization.md b/anti-static-analysis/executable-code-virtualization.md index 0414046..ee7b230 100644 --- a/anti-static-analysis/executable-code-virtualization.md +++ b/anti-static-analysis/executable-code-virtualization.md @@ -46,7 +46,7 @@ Virtualized code is a software protection technique. Themida is a commercial too |Name|Date|Method|Description| |---|---|---|---| -|[**Locky Bart**](../xample-malware/locky-bart.md)|January 2017|--|Code virtualization is added to the Locky Bart binary using WPProtect. [[2]](#2)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Code virtualization is added to the Locky Bart binary using WPProtect. [[2]](#2)| ## References diff --git a/anti-static-analysis/software-packing.md b/anti-static-analysis/software-packing.md index 45c2fc1..d9d64e0 100644 --- a/anti-static-analysis/software-packing.md +++ b/anti-static-analysis/software-packing.md @@ -57,12 +57,13 @@ This description refines the ATT&CK **Obfuscated Files or Information: Software |Name|Date|Method|Description| |---|---|---|---| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip samples are packed with different custom packers. [[3]](#3)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|The malware comes packed by a crypter/FUD [[4]](#4)| -|[**Conficker**](../xample-malware/conficker.md)|2008|F0001.008|Conficker is propagated as a DLL which has been backed using the UPX packer [[5]](#5)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|Has a custom packer to obfuscate itself [[7]](#7)| -|[**Emotet**](../xample-malware/emotet.md)|2018|F0001.005|Emotet uses custom packers which first decrypt the loaders and the loaders decrypt and load Emotet's main payloads [[8]](#8)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Has the option to compress its payload using UPX or MPRESS [[6]](#6)| +|[**Redhip**](../xample-malware/redhip.md)|2011|--|Redhip samples are packed with different custom packers. [[3]](#3)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|The malware comes packed by a crypter/FUD. [[4]](#4)| +|[**Conficker**](../xample-malware/conficker.md)|2008|F0001.008|Conficker is propagated as a DLL which has been backed using the UPX packer. [[5]](#5)| +|[**DarkComet**](../xample-malware/dark-comet.md)|2008|--|DarkComet has the option to compress its payload using UPX or MPRESS. [[6]](#6)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|The malware has a custom packer to obfuscate itself. [[7]](#7)| +|[**Emotet**](../xample-malware/emotet.md)|2018|F0001.005|Emotet uses custom packers which first decrypt the loaders and the loaders decrypt and load Emotet's main payloads. [[8]](#8)| + ## References @@ -70,7 +71,7 @@ This description refines the ATT&CK **Obfuscated Files or Information: Software [2] Jiang Ming et al, Towards Paving the Way for Large-Scale Windows Malware Analysis: Generic Binary Unpacking with Orders-of-Magnitude Performance Boost, October 2018, https://dl.acm.org/citation.cfm?id=3243771. -[3] https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html +[3] https://web.archive.org/web/20161025013916/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html [4] https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan @@ -82,7 +83,3 @@ This description refines the ATT&CK **Obfuscated Files or Information: Software [8] https://documents.trendmicro.com/assets/white_papers/ExploringEmotetsActivities_Final.pdf -[9] https://blog.malwarebytes.com/threat-analysis/2016/07/untangling-kovter/ - -[10] https://web.archive.org/web/20161025013916/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html - diff --git a/collection/input-capture.md b/collection/input-capture.md index 8b12eb7..f0e6a6d 100644 --- a/collection/input-capture.md +++ b/collection/input-capture.md @@ -42,10 +42,11 @@ See ATT&CK: **Input Capture ([T1056](https://attack.mitre.org/techniques/T1056), |Name|Date|Method|Description| |---|---|---|---| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|The malware injects itself into a browser and captures user input data [[1]](#1)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|Injects HTML into browser session to collect sensitive online banking information when the victim performs their online banking [[2]](#2)| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|--|Can capture audio and video [[4]](#4)| -|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer monitors keyboard and mouse activity to determine if the machine is in use [[3]](#3)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|The malware injects itself into a browser and captures user input data. [[1]](#1)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|The malware injects HTML into a browser session to collect sensitive online banking information when the victim performs their online banking. [[2]](#2)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy can capture audio and video. [[4]](#4)| +|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer monitors keyboard and mouse activity to determine if the machine is in use. [[5]](#5)| + ## References diff --git a/collection/keylogging.md b/collection/keylogging.md index 2ac85b3..fdcc01c 100644 --- a/collection/keylogging.md +++ b/collection/keylogging.md @@ -44,16 +44,20 @@ See ATT&CK: **Input Capture: Keylogging ([T1056.001](https://attack.mitre.org/te |Name|Date|Method|Description| |---|---|---|---| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|F0002, F0002.002|Please see the Hupigon malware page for details. [[1]](#1)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Keylogger plugin allows for collection of keystrokes [[3]](#3)| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|--|Can capture keystrokes [[5]](#5)| -|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK collects user keystrokes [[6]](#6)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|F0002, F0002.002|Please see the Dark Comet malware page for details. [[4]](#4)| -|[**Kovter**](../xample-malware/kovter.md)|2016|F0002.002|Log keystrokes via polling (This capa rule had 1 match) [[7]](#7)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|F0002.001, F0002.002|Please see the Redhip malware page for details. [[7]](#7)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|F0002.002|Log keystrokes via polling (This capa rule had 7 matches) [[7]](#7)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|The malware logs keystrokes to a file [[2]](#2)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|F0002.002|Log keystrokes via polling (This capa rule had 1 match) [[7]](#7)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Certain variants of the malware may have keylogging functionality. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|F0002.002|Malware logs keystrokes via polling. [[9]](#9)| +|[**UP007**](../xample-malware/up007.md)|2016|--|The malware logs keystrokes to a file. [[2]](#2)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy's keylogger plugin allows for the collection of keystrokes. [[3]](#3)| +|[**DarkComet**](../xample-malware/dark-comet.md)|2008|--|DarkComet can capture keystrokes. [[4]](#4)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|F0002.002|Malware logs keystrokes via polling. [[9]](#9)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy can capture keystrokes. [[5]](#5)| +|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK collects user keystrokes. [[6]](#6)| +|[**Kovter**](../xample-malware/kovter.md)|2016|F0002.002|Malware logs keystrokes via polling. [[9]](#9)| +|[**Redhip**](../xample-malware/redhip.md)|2011|F0002.001|Malware logs keystrokes via application hook. [[9]](#9)| +|[**Redhip**](../xample-malware/redhip.md)|2011|F0002.002|Malware logs keystrokes via polling. [[9]](#9)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|F0002.002|Malware logs keystrokes via polling. [[9]](#9)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|F0002.002|Malware logs keystrokes via polling. [[9]](#9)| + ## References @@ -73,3 +77,5 @@ See ATT&CK: **Input Capture: Keylogging ([T1056.001](https://attack.mitre.org/te [8] https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf +[9] capa v4.0, analyzed at MITRE on 10/12/2022 + diff --git a/collection/screen-capture.md b/collection/screen-capture.md index 9cba635..74ee764 100644 --- a/collection/screen-capture.md +++ b/collection/screen-capture.md @@ -43,13 +43,14 @@ See ATT&CK: **Screen Capture ([T1113](https://attack.mitre.org/techniques/T1113/ |Name|Date|Method|Description| |---|---|---|---| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--| GoBotKR is capable of capturing screenshots. [[1]](#1)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Screenshot plugin allows for collection of screenshots [[2]](#2)| -|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK takes snapshots of deskop and window contents [[4]](#4)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|E1113, E1113.m01|Please see the Dark Comet malware page for details. [[3]](#3)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1113.m01|Capture screenshot (This capa rule had 2 matches) [[5]](#5)| -|[**Kovter**](../xample-malware/kovter.md)|2016|E1113.m01|Capture screenshot (This capa rule had 1 match) [[5]](#5)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|E1113.m01|Capture screenshot (This capa rule had 2 matches) [[5]](#5)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR is capable of capturing screenshots. [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy's screenshot plugin allows for collection of screenshots. [[2]](#2)| +|[**DarkComet**](../xample-malware/dark-comet.md)|2008|E1113.m01|DarkComet can take screenshots of the victim's computer. [[3]](#3) [[5]](#5)| +|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK takes snapshots of deskop and window contents. [[4]](#4)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1113.m01|Malware captures screenshots. [[5]](#5)| +|[**Kovter**](../xample-malware/kovter.md)|2016|E1113.m01|Malware captures screenshots. [[5]](#5)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|E1113.m01|Malware captures screenshots. [[5]](#5)| + ## References diff --git a/command-and-control/c2-communication.md b/command-and-control/c2-communication.md index 4eef70c..e9faa90 100644 --- a/command-and-control/c2-communication.md +++ b/command-and-control/c2-communication.md @@ -53,31 +53,44 @@ As "server" and "client" are confusing terminology, we use the terms "controller |**Send Heartbeat**|B0030.007|Heartbeat sent.| |**Send System Information**|B0030.006|Implant sends system information.| |**Server to Client File Transfer**|B0030.003|File is transferred from controller to implant.| -|**Start Interactive Shell**|B0030.016|Start an interactive shell using a built-in program (e.g. cmd.exe, PowerShell, bash). This is often implemented with polling the network connection from the controller for text commands to redirect to the shell's stdin and polling the shell's stdout and stderr to redirect over the network to the controller. This differs from Execute Shell Command because the shell process runs across multiple iterations of the recv-command(s)-send-result loop.| +|**Start Interactive Shell**|B0030.016|Starts an interactive shell using a built-in program (e.g. cmd.exe, PowerShell, bash). This is often implemented with polling the network connection from the controller for text commands to redirect to the shell's stdin and polling the shell's stdout and stderr to redirect over the network to the controller. This differs from Execute Shell Command because the shell process runs across multiple iterations of the recv-command(s)-send-result loop.| ## Use in Malware |Name|Date|Method|Description| |---|---|---|---| -|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|B0030.001, B0030.002|Please see the CryptoWall malware page for details. [[1]](#1)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|B0030.002|GoBotKR receives data from the C2 [[2]](#2)| -|[**Terminator**](../xample-malware/terminator.md)|2013|B0030.001|The malware sends data to C2 [[3]](#3)| -|[**YiSpecter**](../xample-malware/yispecter.md)|2015|B0030.006|Connects to the command and control server using HTTP to send device information [[5]](#5)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0030.011|Ursnif variant Dreambot authenticates and encrypts traffic to C2 server using TOR [[6]](#6)| -|[**Emotet**](../xample-malware/emotet.md)|2018|B0030.010|New email addresses are collected automatically from the victim's address books [[7]](#7)| -|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|B0030.001|CHOPSTICK sends data to the C2 server using HTTP POST requests [[8]](#8)| -|[**CozyCar**](../xample-malware/cozycar.md)|2010|--|CozyCar communicates with a C2 server [[9]](#9)| -|[**EvilBunny**](../xample-malware/evilbunny.md)|2011|--|EvilBunny communicates C2 via HTTP [[10]](#10)| -|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer communicates to a Tor Onion Service via HTTP [[11]](#11)| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|B0030.001, B0030.002, B0030.011|Please see the CryptoLocker malware page for details. [[12]](#12)| -|[**Gamut**](../xample-malware/gamut.md)|2014|B0030.002|The malware receives data from C2 [[13]](#13)| -|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|B0030.002|Receive data (This capa rule had 1 match) [[14]](#14)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0030.002, B0030.001|Please see the Hupigon malware page for details. [[14]](#14)| -|[**Kovter**](../xample-malware/kovter.md)|2016|B0030.002, B0030.001|Please see the Kovter malware page for details. [[14]](#14)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0030.001, B0030.002|Please see the Rombertik malware page for details. [[15]](#15)| -|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|B0030.002| The malware receives data from the C2 server. [[16]](#16)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|B0030.002, B0030.001|Please see the UP007 Malware Family malware page for details. [[4]](#4)| +|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|B0030.001|The malware sends a hash value generated from system information. [[1]](#1)| +|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|B0030.002|The malware receives a public key from the C2. [[1]](#1)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|B0030.001|The malware sends a hash value generated from system information. [[14]](#14)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|B0030.002|The malware receives a public key from the C2. [[14]](#14)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|B0030.011|The malware sends a phone-home message with encryption to start. [[14]](#14)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|B0030.002|GoBotKR receives data from the C2. [[2]](#2) [[19]](#19)| +|[**Terminator**](../xample-malware/terminator.md)|2013|B0030.001|The malware sends data to the C2. [[3]](#3)| +|[**UP007**](../xample-malware/up007.md)|2016|B0030.001|The malware sends hardened HTTP headers disguised as Microsoft Update traffic. [[4]](#4)| +|[**UP007**](../xample-malware/up007.md)|2016|B0030.002|The malware receives payloads. [[4]](#4)| +|[**YiSpecter**](../xample-malware/yispecter.md)|2015|B0030.006|The malware connects to the C2 server using HTTP to send device information. [[5]](#5)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0030.011|Ursnif variant Dreambot authenticates and encrypts traffic to the C2 server using TOR. [[6]](#6)| +|[**Emotet**](../xample-malware/emotet.md)|2018|B0030.010|New email addresses are collected automatically from the victim's address books. [[7]](#7)| +|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|B0030.001|CHOPSTICK sends data to the C2 server using HTTP POST requests. [[8]](#8)| +|[**CozyCar**](../xample-malware/cozycar.md)|2010|--|CozyCar communicates with a C2 server. [[9]](#9)| +|[**EvilBunny**](../xample-malware/evilbunny.md)|2011|--|EvilBunny communicates C2 via HTTP. [[10]](#10)| +|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer communicates to a Tor Onion Service via HTTP. [[11]](#11)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0030.001|The malware sends collected data about the system to C2 server. [[12]](#12) [[13]](#13)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0030.002|The C2 server returns Base64 encoded data containing the information about the next command for the loader. [[12]](#12) [[13]](#13)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0030.013|The payload is run by explorer.exe. [[12]](#12) [[13]](#13)| +|[**Gamut**](../xample-malware/gamut.md)|2014|B0030.002|Gamut receives data from the C2. [[15]](#15)| +|[**Gamut**](../xample-malware/gamut.md)|2014|B0030.003|The malware receives files from the C2. [[15]](#15)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|B0030.002|GravityRAT receives data from the C2. [[19]](#19)| +|[**Heriplor**](../xample-malware/heriplor.md)|2012|B0030.002|Heriplor malware has a capability to connect with a C2 to download arbitrary code. [[16]](#16)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0030.001|The malware sends data to the C2. [[17]](#17) [[19]](#19)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0030.002|The malware receives data from the C2. [[19]](#19)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|BB0030.001|The malware sends data to the C2. [[19]](#19)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0030.002|The malware receives data from the C2. [[19]](#19)| +|[**Kovter**](../xample-malware/kovter.md)|2016|B0030.001|The malware sends data to the C2. [[19]](#19)| +|[**Kovter**](../xample-malware/kovter.md)|2016|B0030.002|The malware receives data from the C2. [[19]](#19)| +|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|B0030.002|The malware receives data from the C2 server. [[18]](#18)| + ## Code Snippets @@ -126,15 +139,18 @@ jmp short loc_4019A2 [11] https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clipminer-bitcoin-mining-hijacking -[12] https://www.secureworks.com/research/cryptolocker-ransomware +[12] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ -[13] https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/ +[13] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader -[14] capa v4.0, analyzed at MITRE on 10/12/2022 +[14] https://www.secureworks.com/research/cryptolocker-ransomware -[15] https://blogs.cisco.com/security/talos/rombertik +[15] https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/ -[16] https://blog.malwarebytes.com/threat-analysis/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection/ +[16] https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/troj_heriplor.a -[17] https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke/ +[17] https://blogs.cisco.com/security/talos/rombertik +[18] https://blog.malwarebytes.com/threat-analysis/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection/ + +[19] capa v4.0, analyzed at MITRE on 10/12/2022 diff --git a/command-and-control/domain-name-generation.md b/command-and-control/domain-name-generation.md index c89f3fb..8c22627 100644 --- a/command-and-control/domain-name-generation.md +++ b/command-and-control/domain-name-generation.md @@ -36,11 +36,11 @@ The related **Dynamic Resolution: Domain Generation Algorithms ([T1568.002](http |Name|Date|Method|Description| |---|---|---|---| -|[**Kraken**](../xample-malware/kraken.md)|April 2008|--|Kraken uses a domain generating algorithm to provide new domains. [[2]](#2)| -|[**Conficker**](../xample-malware/conficker.md)|November 2008|--|Conficker uses a domain name generator. [[3]](#3)| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|The malware sends a hash value generated from system information [[4]](#4)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|Ursnif has used a Domain name generation algorithm in the past [[5]](#5)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|B0030.001|The malware sends data to the C2 [[6]](#6)| +|[**Kraken**](../xample-malware/kraken.md)|2008|--|Kraken uses a domain generating algorithm to provide new domains. [[2]](#2)| +|[**Conficker**](../xample-malware/conficker.md)|2008|--|Conficker uses a domain name generator seeded by the current date to ensure that every copy of the virus generates the same names on their respective days. [[3]](#3)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|The malware uses an internal domain generation algorithm. [[4]](#4)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|Previous interations of Ursnif have used a Domain Name Generation algorithm. [[5]](#5)| + ## References @@ -54,5 +54,3 @@ The related **Dynamic Resolution: Domain Generation Algorithms ([T1568.002](http [5] https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality -[6] https://blogs.cisco.com/security/talos/rombertik - diff --git a/command-and-control/ingress-tool-transfer.md b/command-and-control/ingress-tool-transfer.md index 14c7902..5b8e7c1 100644 --- a/command-and-control/ingress-tool-transfer.md +++ b/command-and-control/ingress-tool-transfer.md @@ -38,26 +38,36 @@ See ATT&CK: **Ingress Tool Transfer ([T1105](https://attack.mitre.org/techniques |Name|Date|Method|Description| |---|---|---|---| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Creates a folder on remote computers and then copies its executables (Shamoon and Filerase) into that directory [[2]](#2)| -|[**CozyCar**](../xample-malware/cozycar.md)|2010|--|CozyCar requests a file using SSL to a C2 domain [[3]](#3)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Can download files from remote repository upon instruction [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|The malware receives files from C2 [[4]](#4)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR can download additional files and update itself. [[5]](#5)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|The malware downloads files from C2 [[6]](#6)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|After the Poison Ivy implant is running on the target machine, the attacker can use a Windows GUI controller to control the target computer. [[1]](#1)| +|[**DarkComet**](../xample-malware/dark-comet.md)|2008|--|DarkComet can download files from a remote repository upon instruction. [[2]](#2)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon creates a folder on remote computers and then copies its executables (Shamoon and Filerase) into that directory. [[3]](#3)| +|[**CozyCar**](../xample-malware/cozycar.md)|2010|--|CozyCar requests a file using SSL to a C2 domain. [[4]](#4)| +|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Vobfus downloads its latest version from a remote server. [[5]](#5)| +|[**TEARDROP**](../xample-malware/teardrop.md)|2018|--|TEARDROP executes the decrypted, embedded code buffer, which is a Cobalt Strike RAT. [[6]](#6)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|--|Malware downloads DLLs from the hardcoded URL/remote server. [[7]](#7) [[8]](#8)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR can download additional files and update itself. [[9]](#9)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut receives files from the C2. [[10]](#10)| +|[**UP007**](../xample-malware/up007.md)|2016|--|UP007 downloads files from the C2. [[10]](#10)| + ## References -[1] https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/ +[1] https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy -[2] https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/ +[2] https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/ -[3] https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke +[3] https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/ -[4] https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/ +[4] https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke -[5] https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/ +[5] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ -[6] https://citizenlab.ca/2016/04/between-hong-kong-and-burma/ +[6] https://www.cisa.gov/uscert/ncas/analysis-reports/ar21-039b -[7] https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke/ +[7] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ +[8] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader + +[9] https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/ + +[10] https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/ \ No newline at end of file diff --git a/defense-evasion/alternative-installation-location.md b/defense-evasion/alternative-installation-location.md index b5457b8..9a52d76 100644 --- a/defense-evasion/alternative-installation-location.md +++ b/defense-evasion/alternative-installation-location.md @@ -28,7 +28,7 @@ # Alternative Installation Location -Malware may install itself not as a file on the hard drive. [[1]](#1) +Malware may install itself in areas other than the hard drive. [[1]](#1) ## Methods @@ -41,8 +41,9 @@ Malware may install itself not as a file on the hard drive. [[1]](#1) |Name|Date|Method|Description| |---|---|---|---| -|[**Kovter**](../xample-malware/kovter.md)|2016|B0027.002|Stores malware files in the Registry instead of the hard drive. [[1]](#1)| -|[**SYNful Knock**](../xample-malware/synful-knock.md)|2015|B0027.001|100 memory-resident modules can be installed [[2]](#2)| +|[**Kovter**](../xample-malware/kovter.md)|2016|B0027.002|Kovter stores malware files in the Registry instead of on the hard drive. [[1]](#1)| +|[**SYNful Knock**](../xample-malware/synful-knock.md)|2015|B0027.001|100 memory-resident modules can be installed. [[2]](#2)| + ## References diff --git a/defense-evasion/bootkit.md b/defense-evasion/bootkit.md index 66caf39..f694f8b 100644 --- a/defense-evasion/bootkit.md +++ b/defense-evasion/bootkit.md @@ -36,8 +36,9 @@ The MBC also associates the Bootkit behavior with Defense Evasion because the ma |Name|Date|Method|Description| |---|---|---|---| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|An MBR bootkit and a BIOS bootkit targeting Award BIOS. [[1]](#1)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|Can implement malicious code into firmware, allowing read, write, and/or erasure of the UEFI/BIOS firmware [[2]](#2)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|The malware is an MBR bootkit and a BIOS bootkit targeting Award BIOS. [[1]](#1)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|The malware can implement malicious code into firmware, allowing read, write, and/or erasure of the UEFI/BIOS firmware. [[2]](#24)| + ## References diff --git a/defense-evasion/disable-or-evade-security-tools.md b/defense-evasion/disable-or-evade-security-tools.md index 4e2016c..15971d9 100644 --- a/defense-evasion/disable-or-evade-security-tools.md +++ b/defense-evasion/disable-or-evade-security-tools.md @@ -52,8 +52,11 @@ See ATT&CK: **Impair Defenses: Disable or Modify Tools ([T1562.001](https://atta |Name|Date|Method|Description| |---|---|---|---| -|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|Loads ntdll.dll and user32.dll as data files in memory and overwrites the first 8 bytes of those functions, which unhooks the APIs. [[1]](#1)| -|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|Prevents the infected system from installing anti-virus software updates. [[2]](#2)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|Most security products hook some APIs to monitor the behavior of malware. To avoid being identified by this technique, WebCobra loads ntdll.dll and user32.dll as data files in memory and overwrites the first 8 bytes of those functions, which unhooks the APIs. [[1]](#1)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|The malware terminates the following anti-malware services: Window Defender, MBamService (Malwarebytes), SAVService (Sophos AV). [[6]](#6)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|DNSChanger prevents the infected system from installing anti-virus software updates. [[2]](#2)| +|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Vobfus uses GetModuleHandle API to check for the presence of Avast Antivirus. [[5]](#5)| + ## References @@ -65,3 +68,7 @@ See ATT&CK: **Impair Defenses: Disable or Modify Tools ([T1562.001](https://atta [4] Carl Petty, Red Canary, 3/3/2020. Online: https://redcanary.com/blog/heavens-gate-technique-on-linux/ +[5] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ + +[6] https://www.trendmicro.com/en_us/research/18/k/trickbot-shows-off-new-trick-password-grabber-module.html + diff --git a/defense-evasion/hidden-files-and-directories.md b/defense-evasion/hidden-files-and-directories.md index aa759ee..be59ea8 100644 --- a/defense-evasion/hidden-files-and-directories.md +++ b/defense-evasion/hidden-files-and-directories.md @@ -47,8 +47,12 @@ See ATT&CK: **Hide Artifacts: Hidden Files and Directories ([T1564.001](https:// |Name|Date|Method|Description| |---|---|---|---| |[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--| GoBotKR stores itself in a file with Hidden and System attributes. [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|F0005.004|Modifies target files' time to August 2012 as an antiforensic trick [[2]](#2)| -|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK creates a hidden file for temporary storage [[3]](#3)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|F0005.004|Malware modifies target files' time to August 2012 as an antiforensic trick. [[2]](#2)| +|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK creates a hidden file for temporary storage. [[3]](#3)| +|[**Vobfus**](../xample-malware/vobfus.md)|2016|F0005.002|Vobfus is located on external drives or network shares and attaches itself to ZIP and RAR files, other removable drives, and network shares. Vobfus hides folders on the external drive and drops an executable with the same name and a disguised folder icon. [[4]](#4)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|F0005.002|Malware looks for a specific folder on the victim. If the folder doesn't exist, the malware creates the folder on the victim by calling CreateDirectoryA and downloads the remote file into the new folder. [[5]](#5) [[6]](#6)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|F0005.001|The malware also appends the filename and extension .ocx to the ProgramData folder path. [[5]](#5) [[6]](#6)| + ## References @@ -58,3 +62,8 @@ See ATT&CK: **Hide Artifacts: Hidden Files and Directories ([T1564.001](https:// [3] https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf +[4] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ + +[5] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ + +[6] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader diff --git a/defense-evasion/hide-artifacts.md b/defense-evasion/hide-artifacts.md index 2dd53db..55499bd 100644 --- a/defense-evasion/hide-artifacts.md +++ b/defense-evasion/hide-artifacts.md @@ -47,8 +47,8 @@ See ATT&CK: **Hide Artifacts ([T1564](https://attack.mitre.org/techniques/T1564/ |Name|Date|Method|Description| |---|---|---|---| -|[**YiSpecter**](../xample-malware/yispecter.md)|2015|--|Hides icons from iOS's SpringBoard as well as use the same name and logos of system apps to trick iOS power users [[1]](#1)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Stuxnet intercepts IRP requests (reads, writes) to devices (NFTS, FAT, CD-ROM). It monitors directory control IRPs, in particular directory query notifications such that when an application requests the list of files, it returns a Stuxnet-specified subset of the true items. These filters hide the files used by Stuxnet to spread through removalbe drives [[2]](#2)| +|[**YiSpecter**](../xample-malware/yispecter.md)|2015|--|The malware hides icons from iOS's SpringBoard as well as use the same name and logos of system apps to trick iOS power users. [[1]](#1)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Stuxnet intercepts IRP requests (reads, writes) to devices (NFTS, FAT, CD-ROM). It monitors directory control IRPs, in particular directory query notifications, such that when an application requests the list of files, it returns a Stuxnet-specified subset of the true items. These filters hide the files used by Stuxnet to spread through removable drives. [[2]](#2)| ## References diff --git a/defense-evasion/hijack-execution-flow.md b/defense-evasion/hijack-execution-flow.md index ee32b02..5dc6e1e 100644 --- a/defense-evasion/hijack-execution-flow.md +++ b/defense-evasion/hijack-execution-flow.md @@ -58,12 +58,14 @@ See ATT&CK: **Hijack Execution Flow ([T1574](https://attack.mitre.org/techniques |Name|Date|Method|Description| |---|---|---|---| -|**Kronos**|June 2014|--|Kronos hooks the API of processes to prevent detection. [[6]](#6)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|Hooks various DLL exported functions when the component is loaded in their respective Browser application process is running to monitor network traffic [[7]](#7)| -|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|F0015.006| Abuses Microsoft's Dynamic Data Exchange (DDE) protocol [[8]](#8)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|F0015.006|Escalates privilege by impersonating the token. First uses LogonUser and ImpersonateLoggedOnUser, then ImpersonateNamedPipeClient. [[10]](#10)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|F0015.003, F0015.007|Please see the Stuxnet malware page for details. [[11]](#11)| -|[**SYNful Knock**](../xample-malware/synful-knock.md)|2015|--|Hooks IOS functions to call and initialize the malware [[9]](#9)| +|**Kronos**|2014|--|Kronos hooks the API of processes to prevent detection. [[6]](#6)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|The malware hooks various DLL exported functions when the DLL component is loaded into their respective browser application to monitor network traffic. [[7]](#7)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|F0015.006|GravityRAT abuses Microsoft's Dynamic Data Exchange (DDE) protocol. [[8]](#8)| +|[**SYNful Knock**](../xample-malware/synful-knock.md)|2015|--|SYNful Knock hooks iOS functions to call and initialize the malware. [[9]](#9)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|F0015.006|Malware escalates privileges by impersonating the token through using LogonUser and ImpersonateLoggedOnUser then ImpersonateNamedPipeClient. [[10]](#10)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|F0015.003|Stuxnet hooks ntdll.dll to monitor for requests to load specially crafted file names which are mapped to a location specified by Stuxnet. [[11]](#11)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|F0015.007|WTR4141.tmp hooks APIs from kernel32.dll and ntdll.dll and replaces the original code for these functions with code that checks for files with properties pertaining to Stuxnet files. If a request is made to list a file with the specified properties, the response from these APIs is altered to state that the file does not exist, thereby hiding all files with these properties. [[11]](#11)| + ## References diff --git a/defense-evasion/indicator-blocking.md b/defense-evasion/indicator-blocking.md index 1a04c3d..374ff02 100644 --- a/defense-evasion/indicator-blocking.md +++ b/defense-evasion/indicator-blocking.md @@ -43,10 +43,11 @@ See ATT&CK: **Impair Defenses: Indicator Blocking ([T1562.006](https://attack.mi |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Clears windows event logs and removes the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevent strings in the user32.dll.mui of the system [[1]](#1)| -|[**Conficker**](../xample-malware/conficker.md)|2008|--|Terminates various services related to system security and Windows and prevents network access to various websites related to antivirus software [[2]](#2)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|Terminates the following anti-malware services: Window Defender, MBamService (Malwarebytes), SAVService (Sophos AV) [[4]](#4)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Can disable security center functions like anti-virus and firewall [[3]](#3)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|The malware clears windows event logs and removes the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevent strings in the user32.dll.mui of the system. [[1]](#1)| +|[**Conficker**](../xample-malware/conficker.md)|2008|--|The malware terminates various services related to system security and Windows and prevents network access to various websites related to antivirus software. [[2]](#2)| +|[**DarkComet**](../xample-malware/dark-comet.md)|2008|--|The malware can disable security center functions like anti-virus and firewall. [[3]](#3)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|TrickBot terminates the following anti-malware services: Window Defender, MBamService (Malwarebytes), SAVService (Sophos AV). [[4]](#4)| + ## References diff --git a/defense-evasion/install-insecure-or-malicious-configuration.md b/defense-evasion/install-insecure-or-malicious-configuration.md index d7f6c49..9da0a72 100644 --- a/defense-evasion/install-insecure-or-malicious-configuration.md +++ b/defense-evasion/install-insecure-or-malicious-configuration.md @@ -34,12 +34,12 @@ Malware may install malicious configuration settings or may modify existing conf |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Configures the system to the TESTSIGNING boot configuration option to load its unsigned driver component [[1]](#1)| -|[**YiSpecter**](../xample-malware/yispecter.md)|2015|--|Changes iOS Safari's default configuration [[2]](#2)| +|[**Black Energy**](../xample-malware/blackenergy.md)|2007|--|Malware configures the system to the TESTSIGNING boot configuration option to load its unsigned driver component. [[1]](#1)| +|[**YiSpecter**](../xample-malware/yispecter.md)|2015|--|The malware changes iOS Safari's default configuration. [[2]](#2)| + ## References [1] https://blog-assets.f-secure.com/wp-content/uploads/2019/10/15163408/BlackEnergy_Quedagh.pdf [2] http://researchcenter.paloaltonetworks.com/2015/10/yispecter-first-ios-malware-attacks-non-jailbroken-ios-devices-by-abusing-private-apis/ - diff --git a/defense-evasion/modify-registry.md b/defense-evasion/modify-registry.md index ae4a636..2cd3b56 100644 --- a/defense-evasion/modify-registry.md +++ b/defense-evasion/modify-registry.md @@ -38,16 +38,17 @@ See ATT&CK: **Modify Registry ([T1112](https://attack.mitre.org/techniques/T1112 |Name|Date|Method|Description| |---|---|---|---| |[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR can modify registry keys to disable Task Manager, Registry Editor and Command Prompt. [[2]](#2)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|The malware adds many entries to the registry [[3]](#3)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|The malware adds a registry key [[4]](#4)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|The malware modifies the registry during execution [[5]](#5)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Disables remote user account control by enabling the registry key LocalAccountTokenFilterPolicy [[6]](#6)| -|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK may encrypt and store configuration data inside a registry key [[7]](#7)| -|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer edits the registry [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|The malware adds many entries to the registry. [[3]](#3)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|The malware adds a registry key. [[4]](#4)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|The malware modifies the registry during execution. [[5]](#5)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon disables remote user account control by enabling the registry key LocalAccountTokenFilterPolicy. [[6]](#6)| +|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK may encrypt and store configuration data inside a registry key. [[7]](#7)| +|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer edits the registry. [[8]](#8)| + ## References -[1] https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clipminer-bitcoin-mining-hijacking +[1] https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy [2] https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/ @@ -61,5 +62,5 @@ See ATT&CK: **Modify Registry ([T1112](https://attack.mitre.org/techniques/T1112 [7] https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf -[8] https://labs.vipre.com/analysis-of-kovter-a-very-clever-piece-of-malware/#:~:text=Kovter%20copies%20the%20fileless%20persistence,written%20on%20to%20the%20filesystem. +[8] https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clipminer-bitcoin-mining-hijacking diff --git a/defense-evasion/obfuscated-files-or-information.md b/defense-evasion/obfuscated-files-or-information.md index 7a94544..4144aaa 100644 --- a/defense-evasion/obfuscated-files-or-information.md +++ b/defense-evasion/obfuscated-files-or-information.md @@ -60,28 +60,32 @@ Instead of being listed alphabetically, methods have been grouped to better faci |Name|Date|Method|Description| |---|---|---|---| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|E1027.m02|Trojan spyware program that has mainly been used for targeting banking sites. [[4]](#4)| -|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|Obfuscates files. [[5]](#5)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|Malware obfuscates files.[[8]](#8)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|The dropped file is password-protected. Once unzipped, the file contains a DLL file to decrypt the second file (a bin file with an encrypted malicious payload). [[7]](#7)| |[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR uses base64 to obfuscate strings, commands and files. [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|The malware will use a key to decrypt text from a URL to create more malicious code [[2]](#2)| -|[**Netwalker**](../xample-malware/netwalker.md)|2020|--|Netwalker is obfuscated with several layers of encoding, obfuscation, and encryption techniques such as base64, hexademcimal, and XOR [[3]](#3)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|E1027.m05|Encrypt data using RC4 via WinAPI (This capa rule had 1 match) [[7]](#7)| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|E1027.m02|Encode data using XOR (This capa rule had 1 match) [[7]](#7)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|E1027.m02|Encode data using XOR (This capa rule had 13 matches) [[7]](#7)| -|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|E1027.m02|Encode data using XOR (This capa rule had 1 match) [[7]](#7)| -|[**Gamut**](../xample-malware/gamut.md)|2014|E1027.m02|Encode data using XOR (This capa rule had 1 match) [[7]](#7)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1027.m02, E1027.m05|Please see the Hupigon malware page for details. [[7]](#7)| -|[**Kraken**](../xample-malware/kraken.md)|2008|E1027.m02|Encode data using XOR (This capa rule had 2 matches) [[7]](#7)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|E1027.m02|Encode data using XOR (This capa rule had 4 matches) [[7]](#7)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|E1027.m02|Encode data using XOR (This capa rule had 2 matches) [[7]](#7)| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|E1027.m07|Poison Ivy variant encrypts all its strings [[6]](#6)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|E1027.m02|Encode data using XOR (This capa rule had 1 match) [[7]](#7)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|E1027.m02|Encode data using XOR (This capa rule had 5 matches) [[7]](#7)| -|[**SamSam**](../xample-malware/samsam.md)|2015|E1027.m07|SamSam obfuscates functions, class names and strings, including the list of targeted file extensions, the help file contents and environment variables using DES encryption with a fixed hard-coded key and the IV [[8]](#8)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|E1027.m02|Encode data using XOR (This capa rule had 1 match) [[7]](#7)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1027.m01, E1027.m02|Please see the Stuxnet malware page for details. [[9]](#9)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|E1027.m02|Encode data using XOR (This capa rule had 13 matches) [[7]](#7)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|Creates an encrypted Registry key called TorClient to store its data [[10]](#10)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|The malware will use a key to decrypt text from a URL to create more malicious code. [[2]](#2)| +|[**Netwalker**](../xample-malware/netwalker.md)|2020|--|Netwalker is obfuscated with several layers of encoding, obfuscation, and encryption techniques such as Base64, hexademcimal, and XOR. [[3]](#3)| +|[**TEARDROP**](../xample-malware/teardrop.md)|2018|E1027.m05|TEARDROP decrypts an embedded code buffer using an XOR-based stream cipher. [[4]](#4)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1027.m01|The configuration data block is encoded with a NOT XOR 0xFF operation. [[5]](#5)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1027.m02|Stuxnet encodes data using XOR. [[9]](#9)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|The malware creates an encrypted Registry key called TorClient to store its data. [[6]](#6)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|E1027.m02|TrickBot encodes data using XOR. [[9]](#9)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|E1027.m05|BlackEnergy encrypts data using RC4 via WinAPI. [[9]](#9)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|E1027.m02|CryptoLocker encodes data using XOR. [[9]](#9)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|E1027.m02|Dark Comet encodes data using XOR. [[9]](#9)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|E1027.m02|DNSChanger encodes data using XOR. [[9]](#9)| +|[**Gamut**](../xample-malware/gamut.md)|2014|E1027.m02|Gamut encodes data using XOR. [[9]](#9)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1027.m02|Hupigon encodes data using XOR. [[9]](#9)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1027.m05|Hupigon encrypts data using DES. [[9]](#9)| +|[**Kraken**](../xample-malware/kraken.md)|2008|E1027.m02|Kraken encodes data using XOR. [[9]](#9)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|E1027.m02|Locky Bart encodes data using XOR. [[9]](#9)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|E1027.m02|Mebromi encodes data using XOR. [[9]](#9)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|E1027.m02|Redhip encodes data using XOR. [[9]](#9)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|E1027.m02|Rombertik encodes data using XOR. [[9]](#9)| +|[**SamSam**](../xample-malware/samsam.md)|2015|E1027.m07|SamSam obfuscates functions, class names and strings, including the list of targeted file extensions, the help file contents and environment variables using DES encryption with a fixed hard-coded key and the IV. [[10]](#10)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|E1027.m02|Shamoon encodes data using XOR. [[9]](#9)| +|[**UP007**](../xample-malware/up007.md)|2016|E1027.m02|The malware encodes data using XOR. [[9]](#9)| + ## References @@ -91,19 +95,16 @@ Instead of being listed alphabetically, methods have been grouped to better faci [3] https://www.trendmicro.com/en_us/research/20/e/netwalker-fileless-ransomware-injected-via-reflective-loading.html -[4] https://www.trendmicro.com/en_us/research/18/k/trickbot-shows-off-new-trick-password-grabber-module.html +[4] https://www.cisa.gov/uscert/ncas/analysis-reports/ar21-039b -[5] https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/ +[5] https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en -[6] https://www.fortinet.com/blog/threat-research/deep-analysis-of-new-poison-ivy-variant +[6] https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality -[7] capa v4.0, analyzed at MITRE on 10/12/2022 +[7] https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/ -[8] https://blog.talosintelligence.com/2018/01/samsam-evolution-continues-netting-over.html +[8] https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf -[9] https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en - -[10] https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality - -[11] https://blog.malwarebytes.com/threat-analysis/2016/07/untangling-kovter/ +[9] capa v4.0, analyzed at MITRE on 10/12/2022 +[10] https://blog.talosintelligence.com/2018/01/samsam-evolution-continues-netting-over.html diff --git a/defense-evasion/polymorphic-code.md b/defense-evasion/polymorphic-code.md index b21520b..b15a97e 100644 --- a/defense-evasion/polymorphic-code.md +++ b/defense-evasion/polymorphic-code.md @@ -28,7 +28,7 @@ # Polymorphic Code -Polymorphic code, a file with the same functionality but different execution, is created, often on the fly, making it difficult to detect. This behavior includes metamorphic code where the code is changed (not just executed differently), but with the behavior the same. Polymorphic Code behavior is typically identified through analysis of related samples. +Polymorphic code, a file with the same functionality but different execution, is created, often on the fly, making it difficult to detect. This behavior includes metamorphic code where the code is changed (not just executed differently), but with the behavior the same. Polymorphic code behavior is typically identified through analysis of related samples. ## Methods @@ -42,7 +42,7 @@ Polymorphic code, a file with the same functionality but different execution, is |Name|Date|Method|Description| |---|---|---|---| -|[**EvilBunny**](../xample-malware/evilbunny.md)|2011|--|EvilBunny utilizes Lua scripts to exhibit polymorphism [[2]](#2)| +|[**EvilBunny**](../xample-malware/evilbunny.md)|2011|--|EvilBunny utilizes Lua scripts to exhibit polymorphism. [[2]](#2)| ## References diff --git a/defense-evasion/process-injection.md b/defense-evasion/process-injection.md index d5bf2fb..3d65c5b 100644 --- a/defense-evasion/process-injection.md +++ b/defense-evasion/process-injection.md @@ -34,12 +34,12 @@ See ATT&CK: **Process Injection ([T1055](https://attack.mitre.org/techniques/T10 |ID|ATT&CK Sub-Technique|Notes| |---|---|---| -|E1055.001|Dynamic-link Library Injection|Malware creates a thread using CreateRemoteThread (or NtCreateThreadEx, RtlCreateUserThread) and LoadLibrary. The path to the malware's malicious dynamic-link library (DLL) is written in the virtual address space of another process; the malware ensures the remote process loads it by creating a remote thread in the target process. This is one of the most common process injection methods. Called *Classic DLL Injection via CreateRemoteThread and LoadLibrary* in [[1]](#1).| -|E1055.002|Portable Executable Injection|Malware copies its malicious code into an existing open process and causes it to execute via shellcode or by calling CreateRemoteThread (instead of passing the address of the LoadLibrary). Called *Portable Executable Injection* in [[1]](#1).| -|E1055.003|Thread Execution Hijacking|Malware targets an existing thread of a process, avoiding noisy process or thread creations operations. Called *Thread Execution Hijacking* in [[1]](#1).| -|E1055.004|Asynchronous Procedure Call|Malware may leverage Asynchronous Procedure Calls (APC) to force another thread to execute its code by attaching it to the APC Queue of the target thread (using QueueUserAPC / NtQueueApcThread); also called AtomBombing [[3]](#3). Called *APC Injection and AtomBombing* in [[1]](#1).| -|E1055.011|Extra Window Memory Injection|Malware may inject into Explorer tray window’s extra window memory. Called *Extra Window Memory Injection* in [[1]](#1).| -|E1055.012|Process Hollowing|Instead of injecting code into a program, malware can upmap (hollow out) legitimate code from memory of a target process, overwriting it with a malicious executable. Called *Process Hollowing* in [[1]](#1).| +|E1055.001|Dynamic-link Library Injection|Malware creates a thread using CreateRemoteThread (or NtCreateThreadEx, RtlCreateUserThread) and LoadLibrary. The path to the malware's malicious dynamic-link library (DLL) is written in the virtual address space of another process; the malware ensures the remote process loads it by creating a remote thread in the target process. This is one of the most common process injection methods, called *Classic DLL Injection via CreateRemoteThread and LoadLibrary* in [[1]](#1).| +|E1055.002|Portable Executable Injection|Malware copies its malicious code into an existing open process and causes it to execute via shellcode or by calling CreateRemoteThread (instead of passing the address of the LoadLibrary), called *Portable Executable Injection* in [[1]](#1).| +|E1055.003|Thread Execution Hijacking|Malware targets an existing thread of a process, avoiding noisy process or thread creations operations, called *Thread Execution Hijacking* in [[1]](#1).| +|E1055.004|Asynchronous Procedure Call|Malware may leverage Asynchronous Procedure Calls (APC) to force another thread to execute its code by attaching it to the APC Queue of the target thread (using QueueUserAPC / NtQueueApcThread), called AtomBombing [[3]](#3), also called *APC Injection and AtomBombing* in [[1]](#1).| +|E1055.011|Extra Window Memory Injection|Malware may inject into Explorer tray window’s extra window memory, called *Extra Window Memory Injection* in [[1]](#1).| +|E1055.012|Process Hollowing|Instead of injecting code into a program, malware can upmap (hollow out) legitimate code from memory of a target process, overwriting it with a malicious executable, called *Process Hollowing* in [[1]](#1).| Methods not captured by ATT&CK Process Injection sub-techniques are listed below. Note that IAT hooking and inline hooking (aka userland rootkits) are defined as methods under the [Hijack Execution Flow](../defense-evasion/hijack-execution-flow.md) behavior. @@ -57,20 +57,23 @@ Methods not captured by ATT&CK Process Injection sub-techniques are listed below |Name|Date|Method|Description| |---|---|---|---| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|Trojan spyware program that has mainly been used for targeting banking sites. [[11]](#11)| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|--|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[2]](#2)| -|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|Injects minor code into a running process. [[12]](#12)| -|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|--|The malware injects code into a new svchost process [[6]](#6)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1055, E1055.012|Please see the Hupigon malware page for details. [[7]](#7)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|E1055.m05|Bypasses UAC using a Shim Database instructing SndVol.exe to execute cmd.exe instead, allowing for elevated execution [[8]](#8)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1055.001, E1055.m05|Please see the Stuxnet malware page for details. [[9]](#9)| -|[**Netwalker**](../xample-malware/netwalker.md)|2020|E1055.001|Netwalker uses reflective DLL loading to inject from memory [[10]](#10)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|The malware loads multiple DLLs into memory [[4]](#4)| -|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|Attach user process memory (This capa rule had 1 match) [[13]](#13)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|E1055.003|Inject thread (This capa rule had 1 match) [[13]](#13)| +|[**UP007**](../xample-malware/up007.md)|2016|E1055.001|The malware loads multiple DLLs into memory. [[4]](#4)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|The malware injects itself into svchost.exe. [[11]](#11)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy code is injected into explorer.exe. [[2]](#2)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|The malware injects miner code into a running process. [[12]](#12)| +|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|--|The malware injects code into a new svchost process. [[6]](#6)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|The malware injects itself into processes such as cmd.exe and notepad.exe [[7]](#7)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1055.012|The malware uses process replacement. [[13]](#13)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|E1055.m05|BlackEnergy bypasses UAC using a Shim Database instructing SndVol.exe to execute cmd.exe instead, allowing for elevated execution. [[8]](#8)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy injects its dll component into svchost.exe. [[8]](#8)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1055.001|Stuxnet injects the entire DLL into another process and then just calls the particular export. [[9]](#9)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1055.m02|Stuxnet uses Mrxcls.sys driver for persistence. It is registered as a boot start service by creating the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxCIs\"ImagePath" = "%System%\drivers\mrxcls.sys". [[9]](#9)| +|[**Netwalker**](../xample-malware/netwalker.md)|2020|E1055.001|Netwalker uses reflective DLL loading to inject from memory. [[10]](#10)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|The malware can attach user process memory. [[13]](#13)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|E1055.003|The malware can inject threads. [[13]](#13)| + ## References - [1] Ashkan Hosseini, *Ten Process Injection Techniques: A Technical Survey of Common and Trending Process Injection Techniques*, July 2017. https://www.elastic.co/blog/ten-process-injection-techniques-technical-survey-common-and-trending-process [2] https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy @@ -91,13 +94,8 @@ Methods not captured by ATT&CK Process Injection sub-techniques are listed below [10] https://www.trendmicro.com/en_us/research/20/e/netwalker-fileless-ransomware-injected-via-reflective-loading.html -[11] https://www.trendmicro.com/en_us/research/18/k/trickbot-shows-off-new-trick-password-grabber-module.html +[11] https://www.cybereason.com/blog/research/dropping-anchor-from-a-trickbot-infection-to-the-discovery-of-the-anchor-malware [12] https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/ [13] capa v4.0, analyzed at MITRE on 10/12/2022 - -[14] https://www.cybereason.com/blog/research/dropping-anchor-from-a-trickbot-infection-to-the-discovery-of-the-anchor-malware - -[15] https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf - diff --git a/defense-evasion/rootkit.md b/defense-evasion/rootkit.md index 498845a..6c8e3b0 100644 --- a/defense-evasion/rootkit.md +++ b/defense-evasion/rootkit.md @@ -33,16 +33,16 @@ Behaviors of a rootkit: "A rootkit is a collection of computer software, typical See ATT&CK: **Rootkit ([T1014](https://attack.mitre.org/techniques/T1014/))**. -Rootkits may hide artifacts (kernel modules, services, threads, userspace libraries), prevent actions (API unhooking (prevents API hooks installed by the malware instance from being removed), file access (prevents access to the file system, including specific files and/or directories associated with the malware instance), file deletion (prevents files and/or directories associated with the malware instance from being deleted), memory access (prevents access to system memory where the malware instance stores code or data), native API hooking (prevents other software from hooking native system APIs), registry access (prevents access to the Windows registry, either entire registry or particular registry keys/values), registry deletion (prevents deletion of registry keys and/or values associated with the malware instance). +Rootkits may hide artifacts (kernel modules, services, threads, userspace libraries), prevent actions, API unhooking (prevents API hooks installed by the malware instance from being removed), file access (prevents access to the file system, including specific files and/or directories associated with the malware instance), file deletion (prevents files and/or directories associated with the malware instance from being deleted), memory access (prevents access to system memory where the malware instance stores code or data), native API hooking (prevents other software from hooking native system APIs), registry access (prevents access to the Windows registry, either entire registry or particular registry keys/values), and registry deletion (prevents deletion of registry keys and/or values associated with the malware instance). ## Methods |Name|ID|Description| |---|---|---| |**Application Rootkit**|E1014.m12|Application rootkits operate by exchanging standard application files with rootkit files, or changing applications by injecting code or patching.| -|**Bootloader**|E1014.m13|A bootloader rootkit modifies the bootloader, enabling activation before the operating system is started. Also known as a Bootkit. See ATT&CK: [Bootkit](https://attack.mitre.org/techniques/T1542/003/).| +|**Bootloader**|E1014.m13|A bootloader rootkit modifies the bootloader, enabling activation before the operating system is started, also known as a Bootkit. See ATT&CK: [Bootkit](https://attack.mitre.org/techniques/T1542/003/).| |**Hardware/Firmware Rootkit**|E1014.m14|A firmware rootkit compromises hardware (e.g. network card, hard drive), system BIOS, UEFI firmware. LoJack is the first in-the-wild UEFI rootkit. See ATT&CK: [System Firmware](https://attack.mitre.org/techniques/T1542/001/).| -|**Hypervisor/Virtualized Rootkit**|E1014.m15|A hypervisor (virtualized) rootkit hosts the target operating system as a virtual machine, enabling interception of all hardware calls. Also called, virtual-machine-based rootkit (VMBR).| +|**Hypervisor/Virtualized Rootkit**|E1014.m15|A hypervisor (virtualized) rootkit hosts the target operating system as a virtual machine, enabling interception of all hardware calls, also called a virtual-machine-based rootkit (VMBR).| |**Kernel Mode Rootkit**|E1014.m16|Rootkit operates by adding or replacing code in OS, device drivers, loadable kernel modules (LKM). Related to ATT&CK: [Kernel Modules and Extensions](https://attack.mitre.org/techniques/T1547/006/)| |**Memory Rootkit**|E1014.m17|A memory rootkit hids in RAM. Behaviors may include methods to prevent memory access. The lifespan of a memory rootkit is short because it disappears after a system reboot.| @@ -50,8 +50,16 @@ Rootkits may hide artifacts (kernel modules, services, threads, userspace librar |Name|Date|Method|Description| |---|---|---|---| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--| Certain variants of the malware may have rootkit functionality [[3]](#3)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1014.m17|Stuxnet registers custom resource drives signed with a legitimate Realtek digital certificate [[4]](#4)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon has certain variants that may have rootkit functionality. [[3]](#3)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1014.m16|Stuxnet registers custom resource drives signed with a legitimate Realtek digital certificate. [[4]](#4)| + + +## Detection + +Rootkits can be detected by detecting primary rootkit behaviors: Hide Artifacts, Impair Defenses, and Highjack Execution Flow. Hidden artifacts include kernel modules (hides use of kernel modules used by the malware instance), services (hides any system services that the malware instance creates or injects itself into), threads (hides one or more threads that belong to the malware instance), and userspace libraries (hides use of userspace libraries used by the malware instance). + +Rootkits can also be detected via memory dump analysis or virtual machine introspection. + ## References diff --git a/defense-evasion/self-deletion.md b/defense-evasion/self-deletion.md index 56d004d..ea86c4b 100644 --- a/defense-evasion/self-deletion.md +++ b/defense-evasion/self-deletion.md @@ -46,15 +46,15 @@ See ATT&CK: **Indicator Removal on Host: Uninstall Malicious Application ([T1630 |Name|Date|Method|Description| |---|---|---|---| -|[**Terminator**](../xample-malware/terminator.md)|2013|F0007.001|Evades sandboxes by terminating and removing itself (DW20.exe) after installation. [[1]](#1)| -|[**CozyCar**](../xample-malware/cozycar.md)|2010|--|CozyCar has a dll file that serves as a cleanup mechanism for its dropped binary [[2]](#2)| -|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|--|The malware will monitor if a specific file gets deleted, and then will delete itself. [[3]](#3)| +|[**Terminator**](../xample-malware/terminator.md)|2013|F0007.001|The RAT evades sandboxes by terminating and removing itself (DW20.exe) after installation. [[1]](#1)| +|[**CozyCar**](../xample-malware/cozycar.md)|2010|--|CozyCar has a dll file that serves as a cleanup mechanism for its dropped binary. [[2]](#2)| +|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|--|The malware will monitor if a specific file gets deleted and then will delete itself. [[3]](#3)| + ## References -[1] https://www.mandiant.com/resources/hot-knives-through-butter-evading-file-based-sandboxes +[1] https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2013/FireEye-Terminator_RAT.pdf -[2] https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke/ +[2] https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke [3] https://blog.malwarebytes.com/threat-analysis/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection/ - diff --git a/discovery/analysis-tool-discovery.md b/discovery/analysis-tool-discovery.md index db79ae7..1e0168d 100644 --- a/discovery/analysis-tool-discovery.md +++ b/discovery/analysis-tool-discovery.md @@ -40,19 +40,22 @@ This behavior corresponds to simple, general discovery of analysis tools. Behavi |**Known Window**|B0013.009|Malware may detect an analysis tool via the presence of a known window.| |**Known Windows Class Name**|B0013.010|Running program windows are checked to see if any windows class name contains a string indicating that an analysis tool is running. For example, 'WinDbgFrameClass' is Windbg main window’s class name. [2]| |**Process detection**|B0013.001|Malware can scan for the process name associated with common analysis tools.| -|**Process detection - Debuggers**|B0013.002|Malware can scan for the process name associated with common analysis tools. OllyDBG / ImmunityDebugger / WinDbg / IDA Pro| -|**Process detection - PCAP Utilities**|B0013.004|Malware can scan for the process name associated with common analysis tools. Wireshark / Dumpcap| -|**Process detection - PE Utilities**|B0013.006|Malware can scan for the process name associated with common analysis tools. ImportREC / PETools / LordPE| -|**Process detection - Process Utilities**|B0013.005|Malware can scan for the process name associated with common analysis tools. ProcessHacker / SysAnalyzer / HookExplorer / SysInspector| -|**Process detection - Sandboxes**|B0013.007|Malware can scan for the process name associated with common analysis tools. Joe Sandbox, etc.| -|**Process detection - SysInternals Suite Tools**|B0013.003|Malware can scan for the process name associated with common analysis tools. Process Explorer / Process Monitor / Regmon / Filemon, TCPView, Autoruns| +|**Process detection - Debuggers**|B0013.002|Malware can scan for the process name associated with common analysis tools - OllyDBG / ImmunityDebugger / WinDbg / IDA Pro.| +|**Process detection - PCAP Utilities**|B0013.004|Malware can scan for the process name associated with common analysis tools - Wireshark / Dumpcap.| +|**Process detection - PE Utilities**|B0013.006|Malware can scan for the process name associated with common analysis tools - ImportREC / PETools / LordPE.| +|**Process detection - Process Utilities**|B0013.005|Malware can scan for the process name associated with common analysis tools - ProcessHacker / SysAnalyzer / HookExplorer / SysInspector.| +|**Process detection - Sandboxes**|B0013.007|Malware can scan for the process name associated with common analysis tools - Joe Sandbox, etc.| +|**Process detection - SysInternals Suite Tools**|B0013.003|Malware can scan for the process name associated with common analysis tools - Process Explorer / Process Monitor / Regmon / Filemon, TCPView, Autoruns.| ## Use in Malware |Name|Date|Method|Description| |---|---|---|---| -|[**Emotet**](../xample-malware/emotet.md)|2018|B0013.002|If it recieves a response from the c2 server stating a debugging-related tool is in the list of running processes, it recieves an "upgrade" command which calls the ShellExecuteW function and exits [[1]](#1)| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|B0013, B0013.010|Please see the Poison-Ivy malware page for details. [[2]](#2)| +|[**Emotet**](../xample-malware/emotet.md)|2018|B0013.002|If Emotet receives a response from the C2 server stating a debugging-related tool is in the list of running processes, it recieves an "upgrade" command which calls the ShellExecuteW function and exits. [[1]](#1)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy Variant runs a threat to check if any analysis tools are running by creating specially named pipes that are created by various analysis tools. If one of the named pipes cannot be created, it means one of the analysis tools is running. [[2]](#2) [[3]](#3)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|B0013.010|Poison Ivy goes through all the running program windows to check if any Windows class name contains a special string to determine if an analysis tool is running. [[2]](#2) [[3]](#3)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|B0013.004|When infecting a x64 architecture system, the malware terminates if Wireshark is running on the system. [[4]](#4)| + ## References @@ -60,3 +63,6 @@ This behavior corresponds to simple, general discovery of analysis tools. Behavi [2] https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf +[3] https://www.fortinet.com/blog/threat-research/deep-analysis-of-new-poison-ivy-variant + +[4] https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/ diff --git a/discovery/application-window-discovery.md b/discovery/application-window-discovery.md index 4e31bc9..f31180c 100644 --- a/discovery/application-window-discovery.md +++ b/discovery/application-window-discovery.md @@ -39,12 +39,12 @@ Malware may attempt to get a listing of open application windows. |Name|Date|Method|Description| |---|---|---|---| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|E1010.m01|Get graphical window text (This capa rule had 2 matches) [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|E1010.m01|Get graphical window text (This capa rule had 1 match) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1010.m01|Get graphical window text (This capa rule had 1 match) [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|E1010.m01|Get graphical window text (This capa rule had 2 matches) [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|E1010.m01|Get graphical window text (This capa rule had 2 matches) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|E1010.m01|Get graphical window text (This capa rule had 1 match) [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|E1010.m01|DarkComet gets graphical window texts. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|E1010.m01|Gamut gets graphical window texts. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1010.m01|Hupigon gets graphical window texts. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|E1010.m01|Kovter gets graphical window texts. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|E1010.m01|Rombertik gets graphical window texts. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|E1010.m01|UP007 gets graphical window text. [[1]](#1)| ## References diff --git a/discovery/code-discovery.md b/discovery/code-discovery.md index 3e1bed6..3ad7e94 100644 --- a/discovery/code-discovery.md +++ b/discovery/code-discovery.md @@ -41,17 +41,17 @@ Malware may inspect code or enumerate aspects. |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|B0046.001|Enumerate PE sections (This capa rule had 1 match) [[1]](#1)| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|B0046.001|Enumerate PE sections (This capa rule had 1 match) [[1]](#1)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|B0046.001|Enumerate PE sections (This capa rule had 3 matches) [[1]](#1)| -|[**Emotet**](../xample-malware/emotet.md)|2018|B0046.001|Enumerate pe sections (this capa rule had 1 match) [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|B0046.001|Enumerate PE sections (This capa rule had 1 match) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0046.001|Enumerate PE sections (This capa rule had 3 matches) [[1]](#1)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|B0046.001|Enumerate PE sections (This capa rule had 2 matches) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|B0046.002|Inspect section memory permissions (This capa rule had 1 match) [[1]](#1)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|B0046.001|Enumerate PE sections (This capa rule had 1 match) [[1]](#1)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|B0046.002|Inspect section memory permissions (This capa rule had 2 matches) [[1]](#1)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0046.001|Enumerate PE sections (This capa rule had 1 match) [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|B0046.001|BlackEnergy enumerates PE sections. [[1]](#1)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|B0046.001|CryptoLocker enumerates PE sections. [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|B0046.001|DarkComet enumerates PE sections. [[1]](#1)| +|[**Emotet**](../xample-malware/emotet.md)|2018|B0046.001|Emotet enumerates PE sections. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|B0046.001|Gamut enumerates PE sections. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0046.001|Hupigon enumerates PE sections. [[1]](#1)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|B0046.001|Locky Bart enumerates PE sections. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|B0046.002|Redhip inspects section memory permissions. [[1]](#1)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|B0046.001|Stuxnet enumerates PE sections. [[1]](#1)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|B0046.002|TrickBot inspects section memory permissions. [[1]](#1)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0046.001|Ursnif enumerates PE sections. [[1]](#1)| ## References diff --git a/discovery/file-and-directory-discovery.md b/discovery/file-and-directory-discovery.md index 56077ca..7af0535 100644 --- a/discovery/file-and-directory-discovery.md +++ b/discovery/file-and-directory-discovery.md @@ -41,23 +41,27 @@ Malware may enumerate files and directories or may search for specific files or |Name|Date|Method|Description| |---|---|---|---| -|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|--|The malware searches for user files before encrypting them [[1]](#1)| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|The malware searches for user files before encrypting them [[2]](#2)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|Collects local files with specified file extensions and information from the victim's machine [[3]](#3)| -|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|Enumerate files on windows (This capa rule had 3 matches) [[4]](#4)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1083, E1083.m01|Please see the Hupigon malware page for details. [[4]](#4)| -|[**Kovter**](../xample-malware/kovter.md)|2016|E1083.m01|Access the Windows event log (This capa rule had 2 matches) [[4]](#4)| -|[**SamSam**](../xample-malware/samsam.md)|2015|--|Enumerate files on windows (This capa rule had 1 match) [[4]](#4)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Enumerate files on windows (This capa rule had 1 match) [[4]](#4)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Get common file path (This capa rule had 3 matches) [[4]](#4)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Get file version info (This capa rule had 1 match) [[4]](#4)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Get common file path (This capa rule had 5 matches) [[4]](#4)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|Check if file exists (This capa rule had 1 match) [[4]](#4)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Get file size (This capa rule had 1 match) [[4]](#4)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Get file size (This capa rule had 1 match) [[4]](#4)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Get file size (This capa rule had 3 matches) [[4]](#4)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Get file version info (This capa rule had 1 match) [[4]](#4)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Get common file path (This capa rule had 1 match) [[4]](#4)| +|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|--|The malware searches for user files before encrypting them. [[1]](#1)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|The malware searches for user files before encrypting them. [[2]](#2)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|The malware collects machine information and local files with specified file extensions. [[3]](#3)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|--|Malware verifies that the folder from the first stage loader exists on the system. The malware also checks for the path for the Opera web browser. If it exists, the malware exits. [[4]](#4) [[5]](#5)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|GravityRAT enumerates files on Windows. [[6]](#6)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon enumerates files recursively. [[6]](#6)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1083.m01|Hupigon accesses the Windows event log. [[6]](#6)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter gets file version info. [[6]](#6)| +|[**Kovter**](../xample-malware/kovter.md)|2016|E1083.m01|Kovter accesses the Windows event log. [[6]](#6)| +|[**SamSam**](../xample-malware/samsam.md)|2015|--|SamSam enumerates files on Windows. [[6]](#6)| +|[**UP007**](../xample-malware/up007.md)|2016|--|The malware enumerates files on Windows. [[6]](#6)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|The malware gets the common file path. [[6]](#6)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|The malware gets file version info. [[6]](#6)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut gets the common file path. [[6]](#6)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR checks if a file exists. [[6]](#6)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|The malware gets a file size. [[6]](#6)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Mebromi gets a file size. [[6]](#6)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip gets a file size. [[6]](#6)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|The malware gets the file version info. [[6]](#6)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon gets a common file path. [[6]](#6)| + ## References @@ -67,5 +71,8 @@ Malware may enumerate files and directories or may search for specific files or [3] https://www.securityartwork.es/wp-content/uploads/2017/07/Trickbot-report-S2-Grupo.pdf -[4] capa v4.0, analyzed at MITRE on 10/12/2022 +[4] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ +[5] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader + +[6] capa v4.0, analyzed at MITRE on 10/12/2022 diff --git a/discovery/system-information-discovery.md b/discovery/system-information-discovery.md index 39655b8..6e8a4e4 100644 --- a/discovery/system-information-discovery.md +++ b/discovery/system-information-discovery.md @@ -42,24 +42,26 @@ See ATT&CK: **System Information Discovery ([T1082](https://attack.mitre.org/tec |Name|Date|Method|Description| |---|---|---|---| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|Trojan spyware program that has mainly been used for targeting banking sites. [[7]](#7)| -|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|Learns about the system so it can drop compatible miner software. [[8]](#8)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|Uses windows command prompt commands to gather system info, task list, installed drivers, and installed programs [[1]](#1)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Uses Systeminfo to gather OS version, system configuration, BIOS, the motherboard, and processor [ [[2]](#2)| -|[**Emotet**](../xample-malware/emotet.md)|2018|--|Collects information related to OS, processes, and sometimes mail client information and sends it to c2 [[4]](#4)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Gathers information (OS version, workgroup status, computer name, domain/workgroup name, file name of infected project file) about each computer in the net to spread itself [[5]](#5)| -|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK collects information from the host including Windows version, CPU architecture, and UAC settings [[6]](#6)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Can collect information about the compter, resources, and operating system version [[3]](#3)| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|Query environment variable (This capa rule had 1 match) [[9]](#9)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Query environment variable (This capa rule had 1 match) [[9]](#9)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR uses wmic, systeminfo and ver commands to collect information about the system and the installed software. [[10]](#10)query environment variable (This capa rule had 2 matches) [[9]](#9)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Query environment variable (This capa rule had 1 match) [[9]](#9)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Get disk information (This capa rule had 1 match) [[9]](#9)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Check OS version (This capa rule had 1 match) [[9]](#9)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Check OS version (This capa rule had 1 match) [[9]](#9)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Get disk size (This capa rule had 1 match) [[9]](#9)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Get hostname (This capa rule had 1 match) [[9]](#9)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Query environment variable (This capa rule had 1 match) [[9]](#9)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|The malware can collect information about the computer, resources, services, installed programs, firmware, and operating system versions. [[7]](#7)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|Malware learns about the system so it can drop compatible miner software. [[8]](#8)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|Malware uses Window's command prompt commands to gather system info, task list, installed drivers, and installed programs. [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Malware uses Systeminfo to gather OS version, system configuration, BIOS, the motherboard, and processor. [[2]](#2)| +|[**DarkComet**](../xample-malware/darkcomet.md)|2008|--|Malware can collect information about the computer, resources, and operating system version. [[3]](#3)| +|[**Emotet**](../xample-malware/emotet.md)|2018|--|Emotet collects information related to OS, processes, and sometimes mail client information and sends it to C2. [[4]](#4)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Malware gathers information (OS version, workgroup status, computer name, domain/workgroup name, file name of infected project file) about each computer in the network to spread itself. [[5]](#5)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Stuxnet checks OS version. [[5]](#5)| +|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|--|CHOPSTICK collects information from the host including Windows version, CPU architecture, and UAC settings. [[6]](#6)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|The malware queries environment variables. [[9]](#9)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|The malware queries environment variables. [[9]](#9)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR uses wmic, systeminfo and ver commands to collect information about the system and the installed software and queries environment variables. [[9]](#9) [[10]](#10)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon queries environment variables. [[9]](#9)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter gets disk information. [[9]](#9)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Mebromi checks OS version. [[9]](#9)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip checks the OS version. [[9]](#9)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Rombertik gets the disk size. [[9]](#9)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon gets the hostname. [[9]](#9)| +|[**UP007**](../xample-malware/up007.md)|2016|--|The malware queries environment variables. [[9]](#9)| + ## References @@ -75,13 +77,10 @@ See ATT&CK: **System Information Discovery ([T1082](https://attack.mitre.org/tec [6] https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf -[7] https://www.trendmicro.com/en_us/research/18/k/trickbot-shows-off-new-trick-password-grabber-module.html +[7] https://www.securityartwork.es/wp-content/uploads/2017/07/Trickbot-report-S2-Grupo.pdf [8] https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/ [9] capa v4.0, analyzed at MITRE on 10/12/2022 [10] https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/ - -[11] https://www.securityartwork.es/wp-content/uploads/2017/07/Trickbot-report-S2-Grupo.pdf - diff --git a/discovery/taskbar-discovery.md b/discovery/taskbar-discovery.md index d04b6b3..0a0ac1f 100644 --- a/discovery/taskbar-discovery.md +++ b/discovery/taskbar-discovery.md @@ -33,7 +33,7 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Find taskbar (This capa rule had 1 match) [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip finds taskbars. [[1]](#1)| ## References diff --git a/execution/command-and-scripting-interpreter.md b/execution/command-and-scripting-interpreter.md index 98e8065..822b25e 100644 --- a/execution/command-and-scripting-interpreter.md +++ b/execution/command-and-scripting-interpreter.md @@ -36,25 +36,26 @@ See ATT&CK: **Command and Scripting Interpreter ([T1059](https://attack.mitre.or |Name|Date|Method|Description| |---|---|---|---| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|--|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)| -|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|From the command line, drops and unzips a password-protected Cabinet archive file. [[1]](#1)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|After the Poison Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|From the command line, the malware drops and unzips a password-protected Cabinet archive file. [[1]](#1)| |[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR uses cmd.exe to execute commands. [[2]](#2)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|The malware executes malicious javascript and powershell [[3]](#3)| -|[**SamSam**](../xample-malware/samsam.md)|2015|--|SamSam uses a batch file for executing the malware and deleting certain components [[4]](#4)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|The wiper component of Shamoon creates a service to run the driver with the command: sc create hdv_725x type= kernel start= demand binpath= WINDOWS\hdv_725x.sys 2>&1 >nul and sends an additional reboot command after completion [[5]](#5)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Stuxnet will store and execute SQL code that will extract and execute Stuxnet from the saved CAB file using xp_cmdshell [[6]](#6)| -|[**EvilBunny**](../xample-malware/evilbunny.md)|2011|--|EvilBunny executes Lua scripts [[7]](#7)| -|[**Netwalker**](../xample-malware/netwalker.md)|2020|--|Netwalker is written and executed in Powershell [[8]](#8)| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|Accept command line arguments (This capa rule had 2 matches) [[9]](#9)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Accept command line arguments (This capa rule had 2 matches) [[9]](#9)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Accept command line arguments (This capa rule had 1 match) [[9]](#9)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Accept command line arguments (This capa rule had 2 matches) [[9]](#9)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Accept command line arguments (This capa rule had 1 match) [[9]](#9)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Accept command line arguments (This capa rule had 1 match) [[9]](#9)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Accept command line arguments (This capa rule had 1 match) [[9]](#9)| -|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|--|The malware installs a script to inject JavaScript script and modify web traffic. [[10]](#10)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|Accept command line arguments (This capa rule had 1 match) [[9]](#9)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Accept command line arguments (This capa rule had 1 match) [[9]](#9)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|The malware executes malicious javascript and powershell. [[3]](#3)| +|[**SamSam**](../xample-malware/samsam.md)|2015|--|SamSam uses a batch file for executing the malware and deleting certain components. [[4]](#4)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|The wiper component of Shamoon creates a service to run the driver with the command: sc create hdv_725x type= kernel start= demand binpath= WINDOWS\hdv_725x.sys 2>&1 >nul and sends an additional reboot command after completion. Shamoon also accepts command line arguments.[[5]](#5)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Stuxnet will store and execute SQL code that will extract and execute Stuxnet from the saved CAB file using xp_cmdshell. [[6]](#6)| +|[**EvilBunny**](../xample-malware/evilbunny.md)|2011|--|EvilBunny executes Lua scripts. [[7]](#7)| +|[**Netwalker**](../xample-malware/netwalker.md)|2020|--|Netwalker is written and executed in Powershell. [[8]](#8)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|The malware accepts command line arguments. [[9]](#9)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|The malware accepts command line arguments. [[9]](#9)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut accepts command line arguments. [[9]](#9)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon accepts command line arguments. [[9]](#9)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Mebromi accepts command line arguments. [[9]](#9)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip accepts command line arguments. [[9]](#9)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|The malware accepts command line arguments. [[9]](#9)| +|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|--|The malware installs a script to inject a JavaScript script and modify web traffic. [[10]](#10)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|TrickBot accepts command line arguments. [[9]](#9)| +|[**UP007**](../xample-malware/up007.md)|2016|--|The malware accepts command line arguments. [[9]](#9)| + ## References diff --git a/execution/conditional-execution.md b/execution/conditional-execution.md index 05a8d95..cc5c3cc 100644 --- a/execution/conditional-execution.md +++ b/execution/conditional-execution.md @@ -32,11 +32,11 @@ # Conditional Execution -Malware checks system environment conditions or characteristics to determine execution path. For example, malware may not run or be dormant unless system conditions are right, or file that is dropped may vary according to execution environment. Conditional execution in malware happens autonomously, not because of an attacker's command. +Malware checks system environment conditions or characteristics to determine execution path. For example, malware may not run or be dormant unless system conditions are right, or a file that is dropped may vary according to the execution environment. Conditional execution in malware happens autonomously, not because of an attacker's command. This behavior is related to the **Dynamic Analysis Evasion ([B0003](../anti-behavioral-analysis/dynamic-analysis-evasion.md))** behavior that obstructs dynamic analysis in a sandbox, emulator, or virtual machine. -Some aspects of this Conditional Execution behavior are related to the [Execution Guardrails (T1480)](https://attack.mitre.org/techniques/T1480) ATT&CK technique; however the ATT&CK technique is not focused on anti-behavioral analysis behaviors. +Some aspects of this Conditional Execution behavior are related to the [Execution Guardrails (T1480)](https://attack.mitre.org/techniques/T1480) ATT&CK technique; however, the ATT&CK technique is not focused on anti-behavioral analysis behaviors. ## Methods @@ -45,23 +45,25 @@ Some aspects of this Conditional Execution behavior are related to the [Executio |**Deposited Keys**|B0025.008|Parts of the code and/or data is encrypted or otherwise relies on data external to the file itself. For example, malware that contains code that is encrypted with a key that is downloaded from a server; malware that only runs if certain other software is installed on the system. Also see Environmental Keys Method.| |**Environmental Keys**|B0025.002|Malware reads certain attributes of the system (BIOS version string, hostname, MAC address, etc.) and encrypts/decrypts portions of its code or data using those attributes as input, thus preventing itself from being run on an unintended system (e.g., sandbox, emulator, etc.). Also see Deposited Keys Method. The subsequently defined ATT&CK sub-technique [Execution Guardrails: Environmental Keying (T1480.001)](https://attack.mitre.org/techniques/T1480/001/) is related to this MBC method. | |**GetVolumeInformation**|B0025.003|This Windows API call is used to get the GUID on a system drive. Malware compares it to a previous (targeted) GUID value and only executes maliciously if they match. This behavior can be mitigated in non-automated analysis environments.| -|**Host Fingerprint Check**|B0025.004|Compare a previously computed host fingerprint(e.g., based on installed applications) to the current system's to determine if the malware instance is still executing on the same system. If not, execution stops, making debugging or sandbox analysis more difficult.| +|**Host Fingerprint Check**|B0025.004|Compare a previously computed host fingerprint (e.g., based on installed applications) to the current system's to determine if the malware instance is still executing on the same system. If not, execution stops, making debugging or sandbox analysis more difficult.| |**Runs as Service**|B0025.007|The malware must be run as a service, which can make behavioral analysis and debugging more difficult. The service may be set up by the malware. Alternatively, the malware may not contain any code to create a new service or modify an existing service, in which case, the service may be set up by another program or manually. [[2]](#2)| |**Secure Triggers**|B0025.005|Code and/or data is encrypted until the underlying system satisfies a preselected condition unknown to the analyst (this is a form of Deposited Keys).| |**Suicide Exit**|B0025.001|Malware terminates its execution based on a trigger condition or value (or because it has completed).| -|**Token Check**|B0025.006|Presence check to allow the program to run (ex: dongle, CD/DVD, key, file, network, etc.). If the token is specific to a hardware element (ex: disk, OS, CPU, NIC MAC, etc.), it is considered fingerprinting.| +|**Token Check**|B0025.006|A token's presence is checked to allow the program to run (ex: dongle, CD/DVD, key, file, network, etc.). If the token is specific to a hardware element (ex: disk, OS, CPU, NIC MAC, etc.), it is considered fingerprinting.| ## Use in Malware |Name|Date|Method|Description| |---|---|---|---| -|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|Drops either Cryptonight or Claymore's Zcash miner, depending on system architecture. [[1]](#1)| -|[**Conficker**](../xample-malware/conficker.md)|2008|B0025, B0025.001|Please see the Conficker malware page for details. [[5]](#5)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0025.004|Macros check if there are at least 50 running processes with a graphical interface, check if a list of blacklisted processes are running, and checks if the application is running in Australia and is NOT affiliated with a select group of networks (Security Research, Hospitals, Universities, Veterans, etc.) [[3]](#3)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Malware only proceeds if it detects the BIOS ROM is Award BIOS [[4]](#4)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0025.007|Run as service (This capa rule had 1 match) [[6]](#6)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|B0025.007|Run as service (This capa rule had 1 match) [[6]](#6)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|B0025.004|Stuxnet checks for specific operating systems on 32-bit machines, registry keys, and dates to profile a potential target machine before execution. If the conditions are not met to be considered a viable target, it will exit execution [[7]](#7)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|The malware executes differently depending on whether it's running on an x86 or x64 system. [[1]](#1)| +|[**Conficker**](../xample-malware/conficker.md)|2008|--|Conficker A variant has a routine that causes the process to suicide exit if the keyboard language is set to Ukranian. [[5]](#5)| +|[**Conficker**](../xample-malware/conficker.md)|2008|B0025.001|Conficker B variant has significantly more suicide logic embedded in its code and employs anti-debugging features to avoid reverse engineering attempts. [[5]](#5)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|B0025.004|Macros check if there are at least 50 running processes with a graphical interface, check if a list of blacklisted processes are running, and checks if the application is running in Australia and is NOT affiliated with a select group of networks (Security Research, Hospitals, Universities, Veterans, etc.). [[3]](#3)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Malware only proceeds if it detects the BIOS ROM is Award BIOS. [[4]](#4)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|B0025.004|Stuxnet checks for specific operating systems on 32-bit machines, registry keys, and dates to profile a potential target machine before execution. If the conditions are not met to be considered a viable target, it will exit execution. [[6]](#6)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|B0025.007|Hupigon can run as a service. [[7]](#7)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|B0025.007|Shamoon can run as a service. [[7]](#7)| + ## References @@ -73,9 +75,9 @@ Some aspects of this Conditional Execution behavior are related to the [Executio [4] https://www.webroot.com/blog/2011/09/13/mebromi-the-first-bios-rootkit-in-the-wild/ -[5] https://en.wikipedia.org/wiki/Conficker +[5] http://www.csl.sri.com/users/vinod/papers/Conficker/ -[6] capa v4.0, analyzed at MITRE on 10/12/2022 +[6] https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en -[7] https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en +[7] capa v4.0, analyzed at MITRE on 10/12/2022 diff --git a/execution/execution-dependency.md b/execution/execution-dependency.md index 6fb4609..eae5aae 100644 --- a/execution/execution-dependency.md +++ b/execution/execution-dependency.md @@ -28,4 +28,4 @@ # Execution Dependency -Software may require certain run-time or library dependencies consistent with normal software development and deployment. For example, software may require the presence of a .NET or Java runtime or to be run by a webserver that supports PHP. Unlike in **Conditional Execution ([B0025](../execution/conditional-execution.md))** this dependency is not because of an explicit check coded into the malware by the author. +Software may require certain run-time or library dependencies consistent with normal software development and deployment. For example, software may require the presence of a .NET or Java runtime or to be run by a webserver that supports PHP. Unlike in **Conditional Execution ([B0025](../execution/conditional-execution.md))**, this dependency is not because of an explicit check coded into the malware by the author. diff --git a/execution/exploitation-for-client-execution.md b/execution/exploitation-for-client-execution.md index 16c3ffd..6d96866 100644 --- a/execution/exploitation-for-client-execution.md +++ b/execution/exploitation-for-client-execution.md @@ -41,8 +41,8 @@ See ATT&CK: **Exploitation for Client Execution ([T1203](https://attack.mitre.or |Name|ID|Description| |---|---|---| |**File Transfer Protocol (FTP) Servers**|E1203.m03|Malware leverages an FTP server.| -|**Java-based Web Servers**|E1203.m02|| -|**Red Hat JBoss Enterprise Products**|E1203.m04|| +|**Java-based Web Servers**|E1203.m02|Malware leverages a Java-based web server.| +|**Red Hat JBoss Enterprise Products**|E1203.m04|Malware leverages JBoss Enterprise products.| |**Remote Desktop Protocols**|E1203.m01|RDP is used by malware.| |**Sysinternals**|E1203.m05|Sysinternals tools are used for additional command line functionality.| |**Windows Utilities**|E1203.m06|One or more Windows utilities are used.| diff --git a/execution/install-additional-program.md b/execution/install-additional-program.md index 5bee04b..2c88aba 100644 --- a/execution/install-additional-program.md +++ b/execution/install-additional-program.md @@ -30,25 +30,28 @@ Installs another, different program on the system. The additional program can be any secondary module; examples include backdoors, malicious drivers, kernel modules, and OS X Apps. -Malware that installs another component is called a "dropper." If the code is contained in the malware, it's a "single stage" dropper; "two stage" droppers download the code from a remote location (the associated download behavior is covered by the **Ingress Tool Transfer ([E1105](../command-and-control/ingress-tool-transfer.md))** behavior. +Malware that installs another component is called a "dropper." If the code is contained in the malware, it's a "single stage" dropper; "two stage" droppers download the code from a remote location (the associated download behavior is covered by **Ingress Tool Transfer ([E1105](../command-and-control/ingress-tool-transfer.md))**). ## Use in Malware |Name|Date|Method|Description| |---|---|---|---| -|[**WebCobra**](../xample-malware/webcobra.md)|November 2018|--|Drops software to mine for cryptocurrency. [[1]](#1)| -|[**Geneio**](../xample-malware/geneio.md)|August 2015|--|Geneio installs the browser extension ~/Library/Safari/Extensions/Omnibar.safariextz. It also creates app files. [[7]](#7)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|The malware downloads and executes Claymore's Zcash miner from a remote server. [[1]](#1)| +|[**Geneio**](../xample-malware/geneio.md)|2015|--|Malware tricks OS X keychain to create application files. Malware also installs the browser extension Omnibar.safariextz. [[10]](#10)| |[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR reinstalls its running instance if it is removed. [[3]](#3)| -|[**MazarBot**](../xample-malware/mazarbot.md)|2016|--|Installs a backdoor. [[8]](#8)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Malware contains a dropper that installs additional programs like Cbrom.exe. [[9]](#9)| -|[**YiSpecter**](../xample-malware/yispecter.md)|2015|--|Can download and install arbitrary iOS apps. [[10]](#10)| -|[**CozyCar**](../xample-malware/cozycar.md)|2010|--|Upon execution, CozyCar drops a decoy file and a secondary dropper [[5]](#5)| -|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer drops a file masquerading as a Control Panel (CPL) file [[6]](#6)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Contain an embedded PE file (This capa rule had 1 match) [[11]](#11)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Contain an embedded PE file (This capa rule had 1 match) [[11]](#11)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Contain an embedded PE file (This capa rule had 1 match) [[11]](#11)| +|[**MazarBot**](../xample-malware/mazarbot.md)|2016|--|MazarBot installs a backdoor. [[14]](#14)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Malware contains a dropper that installs additional programs like Cbrom.exe. [[11]](#11)| +|[**YiSpecter**](../xample-malware/yispecter.md)|2015|--|The malware can download and install arbitrary iOS apps. [[13]](#13)| +|[**UP007**](../xample-malware/up007.md)|2016|--|The malware is a dropper that creates multiple files. [[4]](#4)| +|[**CozyCar**](../xample-malware/cozycar.md)|2010|--|Upon execution, CozyCar drops a decoy file and a secondary dropper. [[5]](#5)| +|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer drops a file masquerading as a Control Panel (CPL) file. [[6]](#6)| +|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Vobfus downloads malware from other malware families. [[7]](#7)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|--|Malware drops the first loader which is responsible for loading the main loader into memory. [[8]](#8) [[9]](#9)| |[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|--|The malware installs an open-source program called mitmproxy. [[12]](#12)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|The malware is a dropper that creates multiple files [[4]](#4)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|The malware contains an embedded PE file. [[15]](#15)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut contains an embedded PE file. [[15]](#15)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip contains an embedded PE file. [[15]](#15)| + ## References @@ -64,17 +67,20 @@ Malware that installs another component is called a "dropper." If the code is co [6] https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clipminer-bitcoin-mining-hijacking -[7] https://blog.malwarebytes.org/mac/2015/08/genieo-installer-tricks-keychain/ +[7] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ -[8] https://us.norton.com/internetsecurity-emerging-threats-mazar-bot-malware-invades-and-erases-android-devices.html +[8] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ -[9] https://www.webroot.com/blog/2011/09/13/mebromi-the-first-bios-rootkit-in-the-wild/ +[9] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader -[10] http://researchcenter.paloaltonetworks.com/2015/10/yispecter-first-ios-malware-attacks-non-jailbroken-ios-devices-by-abusing-private-apis/ +[10] https://blog.malwarebytes.org/mac/2015/08/genieo-installer-tricks-keychain/ -[11] capa v4.0, analyzed at MITRE on 10/12/2022 +[11] https://www.webroot.com/blog/2011/09/13/mebromi-the-first-bios-rootkit-in-the-wild/ [12] https://blog.malwarebytes.com/threat-analysis/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection/ -[13] https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke/ +[13] http://researchcenter.paloaltonetworks.com/2015/10/yispecter-first-ios-malware-attacks-non-jailbroken-ios-devices-by-abusing-private-apis/ +[14] https://us.norton.com/internetsecurity-emerging-threats-mazar-bot-malware-invades-and-erases-android-devices.html + +[15] capa v4.0, analyzed at MITRE on 10/12/2022 \ No newline at end of file diff --git a/execution/remote-commands.md b/execution/remote-commands.md index 443e177..73677ae 100644 --- a/execution/remote-commands.md +++ b/execution/remote-commands.md @@ -55,9 +55,12 @@ Autonomous behaviors - those done by the malware without an active attacker - sh |Name|Date|Method|Description| |---|---|---|---| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|Commands sent by a remote user can archive/upload files, capture screenshots, clear cookies, download execute other files, list running processes, reboot the affected system, steal certificates and cookies, update/download a configuration file, upload a log file which contains stolen information [[1]](#1)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Infected bots receive commands from botmaster to load plugins associated with botmaster's goals [[2]](#2)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|Receives various commands from c2 server. [[3]](#3)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|The malware commands sent by a remote user can archive/upload files, capture screenshots, clear cookies, download/execute other files, list running processes, reboot the affected system, steal certificates and cookies, update/download a configuration file, and upload a log file which contains stolen information. [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Infected bots receive commands from the botmaster to load plugins associated with botmaster's goals. [[2]](#2)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|The malware receives various commands from the C2 server. [[3]](#3)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0011.005|The malware sleeps if it fails to send collected data or execute its commands. [[4]](#4) [[5]](#5)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|B0011.006|The malware loader can uninstall itself from the victim computer. [[4]](#4) [[5]](#5)| + ## References @@ -67,3 +70,6 @@ Autonomous behaviors - those done by the malware without an active attacker - sh [3] https://www.cybereason.com/blog/research/dropping-anchor-from-a-trickbot-infection-to-the-discovery-of-the-anchor-malware +[4] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ + +[5] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader diff --git a/execution/send-email.md b/execution/send-email.md index feea2d8..85137a9 100644 --- a/execution/send-email.md +++ b/execution/send-email.md @@ -38,7 +38,8 @@ This behavior is related to the **Phishing ([T1566](https://attack.mitre.org/tec |---|---|---|---| |[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut probes the infected system's SMTP port 25 by sending a test SMTP transaction to mail.ru and hotmail.com. If port 25 is open, the bot requests the spam template and email list, which it uses to send spam. [[1]](#1)| |[**Bagle**](../xample-malware/bagle.md)|2004|--|Bagle uses its own SMTP engine to mass-mail itself as an attachment from an infected computer. [[2]](#2)| -|[**Emotet**](../xample-malware/emotet.md)|2018|--|Spam email with the Emotet loader is sent automatically [[3]](#3)| +|[**Emotet**](../xample-malware/emotet.md)|2018|--|Spam email with the Emotet loader is sent automatically. [[3]](#3)| + ## References @@ -48,5 +49,3 @@ This behavior is related to the **Phishing ([T1566](https://attack.mitre.org/tec [3] https://securelist.com/the-banking-trojan-emotet-detailed-analysis/69560/ -[4] https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/ - diff --git a/execution/user-execution.md b/execution/user-execution.md index 3628640..5174bd1 100644 --- a/execution/user-execution.md +++ b/execution/user-execution.md @@ -37,10 +37,12 @@ See ATT&CK Technique: **User Execution ([T1204](https://attack.mitre.org/techniq |Name|Date|Method|Description| |---|---|---|---| |[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--| GoBotKR makes their malware look like the torrent content that the user intended to download, in order to entice a user to click on it. [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|The malware relies on a victim to execute itself [[2]](#2)| -|[**Terminator**](../xample-malware/terminator.md)|2013|--|The malware relies on user interaction to execute [[3]](#3)| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|The malware relies on victims to execute [[5]](#5)| -|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|--|A user must execute the malicious program. [[4]](#4)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|The malware relies on a victim to execute itself. [[2]](#2)| +|[**Terminator**](../xample-malware/terminator.md)|2013|--|The malware relies on user interaction to execute. [[3]](#3)| +|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|The malware relies on user interaction to run the executable. [[4]](#4)| +|[**CryptoLocker**](../xample-malware/vobfus.md)|2013|--|The malware relies on victims to execute. [[4]](#4)| +|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|--|The user opens a disk image file which invisibly installs its components. [[6]](#6)| + ## References @@ -50,9 +52,8 @@ See ATT&CK Technique: **User Execution ([T1204](https://attack.mitre.org/techniq [3] https://www.mandiant.com/resources/hot-knives-through-butter-evading-file-based-sandboxes -[4] https://blog.malwarebytes.com/threat-analysis/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection/ +[4] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ [5] https://www.secureworks.com/research/cryptolocker-ransomware -[6] https://paper.seebug.org/papers/APT/APT_CyberCriminal_Campagin/2013/FireEye-Terminator_RAT.pdf - +[6] https://blog.malwarebytes.com/threat-analysis/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection/ diff --git a/exfiltration/archive-collected-data.md b/exfiltration/archive-collected-data.md index 78cd053..704cee4 100644 --- a/exfiltration/archive-collected-data.md +++ b/exfiltration/archive-collected-data.md @@ -48,8 +48,10 @@ See ATT&CK Technique: **Archive Collected Data ([T1560](https://attack.mitre.org |Name|Date|Method|Description| |---|---|---|---| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|E1560.m02|Uses a custom crypter leveraging Microsoft's CryptoAPI to encrypt C2 traffic. C2 update responses seem to have been digitally signed using bcrypt [[1]](#1)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1560.m04|Exfiltrated payloads are XORed with a static 31-byte long byte string found inside Stuxnet and hexified in order to be passed on as an ASCII data parameter in an HTTP request to the C2 servers [[2]](#2)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|E1560.m02|The malware uses a custom crypter leveraging Microsoft's CryptoAPI to encrypt C2 traffic. C2 update responses seem to have been digitally signed using bcrypt. [[1]](#1)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|E1560.m04|Exfiltrated payloads are XORed with a static 31-byte long byte string found inside Stuxnet and hexified in order to be passed on as an ASCII data parameter in an HTTP request to the C2 servers. [[2]](#2)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|E1560.m03|Malware sends data as a Base64 string of JSON. [[3]](#3) [[4]](#4)| + ## References @@ -57,3 +59,6 @@ See ATT&CK Technique: **Archive Collected Data ([T1560](https://attack.mitre.org [2] https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en +[3] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ + +[4] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader diff --git a/impact/clipboard-modification.md b/impact/clipboard-modification.md index d872e7f..d0dc427 100644 --- a/impact/clipboard-modification.md +++ b/impact/clipboard-modification.md @@ -38,11 +38,12 @@ ATT&CK defines Clipboard Modification as a Mobile technique (Android platform). |Name|Date|Method|Description| |---|---|---|---| -|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer monitors the clipboard for cryptocurrency addresses and replaces them with ones controlled by the adversary [[1]](#1)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Write clipboard data (This capa rule had 4 matches) [[2]](#2)| -|[**Emotet**](../xample-malware/emotet.md)|2018|--|Write clipboard data (this capa rule had 1 match) [[2]](#2)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Replace clipboard data (This capa rule had 1 match) [[2]](#2)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Replace clipboard data (This capa rule had 1 match) [[2]](#2)| +|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer monitors the clipboard for cryptocurrency addresses and replaces them with ones controlled by the adversary. [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|The malware writes clipboard data. [[2]](#2)| +|[**Emotet**](../xample-malware/emotet.md)|2018|--|Emotet writes clipboard data. [[2]](#2)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon replaces clipboard data. [[2]](#2)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|The malware replaces clipboard data. [[2]](#2)| + ## References diff --git a/impact/data-destruction.md b/impact/data-destruction.md index 85e1771..e40d258 100644 --- a/impact/data-destruction.md +++ b/impact/data-destruction.md @@ -48,11 +48,12 @@ See ATT&CK: **Data Destruction ([T1485](https://attack.mitre.org/techniques/T148 |Name|Date|Method|Description| |---|---|---|---| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|A 2018 variant includes a component that erases files and then wipes the master boot record, preventing file recovery. [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|If a specific anti-analysis check fails, the malware will overwrite the Master Boot Record or the User's home folder [[2]](#2)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy 2 variant contains a Destroy plugin that destroys data stored on victim hard drives by overwriting file contents [[3]](#3)| -|[**Conficker**](../xample-malware/conficker.md)|2008|--|Resets system restore points and deletes backup files [[4]](#4)| -|[**MazarBot**](../xample-malware/mazarbot.md)|2016|--|Can erase phone data [[5]](#5)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|A 2018 variant includes a component that erases files and then wipes the Master Boot Record (MBR), preventing file recovery. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|If a specific anti-analysis check fails, the malware will overwrite the Master Boot Record or the user's home folder. [[2]](#2)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy 2 variant contains a Destroy plugin that destroys data stored on victim hard drives by overwriting file contents. [[3]](#3)| +|[**Conficker**](../xample-malware/conficker.md)|2008|--|Conficker resets system restore points and deletes backup files. [[4]](#4)| +|[**MazarBot**](../xample-malware/mazarbot.md)|2016|--|MazarBot can erase phone data. [[5]](#5)| + ## References diff --git a/impact/data-encrypted-for-impact.md b/impact/data-encrypted-for-impact.md index 65caf8f..88e30af 100644 --- a/impact/data-encrypted-for-impact.md +++ b/impact/data-encrypted-for-impact.md @@ -46,11 +46,12 @@ See ATT&CK: **Data Encrypted for Impact ([T1486](https://attack.mitre.org/techni |Name|Date|Method|Description| |---|---|---|---| -|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|E1486.001|The malware launches Internet Explorer to show ransom notes [[1]](#1)| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|E1486.001|The malware launches Internet Explorer to show ransom notes [[2]](#2)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Encrypts files for ransom without any connection to the Internet [[3]](#3)| -|[**SamSam**](../xample-malware/samsam.md)|2015|--|SamSam encrypts data to hold for ransom [[4]](#4)| -|[**Netwalker**](../xample-malware/netwalker.md)|2020|--|Netwalker encrypts files for ransom [[5]](#5)| +|[**CryptoWall**](../xample-malware/cryptowall.md)|2014|E1486.001|The malware launches Internet Explorer to show ransom notes. [[1]](#1)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|E1486.001|The malware launches Internet Explorer to show ransom notes. [[2]](#2)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Locky Bart encrypts files for ransom without any connection to the Internet. [[3]](#3)| +|[**SamSam**](../xample-malware/samsam.md)|2015|--|SamSam encrypts data to hold for ransom. [[4]](#4)| +|[**Netwalker**](../xample-malware/netwalker.md)|2020|--|Netwalker encrypts files for ransom. [[5]](#5)| + ## References diff --git a/impact/denial-of-service.md b/impact/denial-of-service.md index 166593f..1dea5d3 100644 --- a/impact/denial-of-service.md +++ b/impact/denial-of-service.md @@ -42,7 +42,7 @@ The related **Network Denial of Service ([T1498](https://attack.mitre.org/techni |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|October 2007|--|Launches distributed denial of service attacks that can target more than one IP address per hostname. [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy launches distributed denial of service attacks that can target more than one IP address per hostname. [[1]](#1)| |[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR has been used to execute endpoint DDoS attacks – for example, TCP Flood or SYN Flood. [[2]](#2)| ## References @@ -51,5 +51,3 @@ The related **Network Denial of Service ([T1498](https://attack.mitre.org/techni [2] https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/ -[3] https://blog-assets.f-secure.com/wp-content/uploads/2019/10/15163408/BlackEnergy_Quedagh.pdf - diff --git a/impact/destroy-hardware.md b/impact/destroy-hardware.md index fd509fa..387a9f1 100644 --- a/impact/destroy-hardware.md +++ b/impact/destroy-hardware.md @@ -32,7 +32,7 @@ # Destroy Hardware -Destroys a physical piece of hardware. For example, malware may cause hardware to overheat. +Malware destroys a physical piece of hardware. For example, malware may cause hardware to overheat. ## Use in Malware diff --git a/impact/disk-wipe.md b/impact/disk-wipe.md index e4c409f..a005593 100644 --- a/impact/disk-wipe.md +++ b/impact/disk-wipe.md @@ -33,13 +33,13 @@ Malware may erase the content of storage devices. This behavior is different than **Data Destruction ([E1485](../impact/data-destruction.md))** because sections of the disk are erased rather than individual files. -This description refines the ATT&CK **Disk Wipe ([T1203](https://attack.mitre.org/techniques/T1561/)**] sub-technique. +This description refines the ATT&CK **Disk Wipe ([T1203](https://attack.mitre.org/techniques/T1561/)**) sub-technique. ## Use in Malware |Name|Date|Method|Description| |---|---|---|---| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|An overwrite component will overwrite the MBR so that the compromised computer can no longer start [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|An overwrite component will overwrite the MBR so that the compromised computer can no longer start. [[1]](#1)| ## References diff --git a/impact/exploit-kit.md b/impact/exploit-kit.md index 351bf83..b37d084 100644 --- a/impact/exploit-kit.md +++ b/impact/exploit-kit.md @@ -36,6 +36,14 @@ An Exploit Kit is a toolkit that exploits vulnerabilities in software to deliver See related ATT&CK Technique: **Exploit Public-Facing Application ([T1190](https://attack.mitre.org/techniques/T1190))**, which relates to Initial Access. Under the Impact objective, exploit behaviors are considered more broadly in MBC. + +## Use in Malware + +|Name|Date|Method|Description| +|---|---|---|---| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|Ursnif is sometimes delivered via exploit kit. [[1]](#1)| + + ## References [1] https://www.cyber.nj.gov/threat-profiles/trojan-variants/ursnif diff --git a/impact/generate-traffic-from-victim.md b/impact/generate-traffic-from-victim.md index 157ec97..1a48a5a 100644 --- a/impact/generate-traffic-from-victim.md +++ b/impact/generate-traffic-from-victim.md @@ -45,9 +45,10 @@ Malware may generate traffic from the victim system such as clicks of advertisin |Name|Date|Method|Description| |---|---|---|---| -|[**DNSChanger**](../xample-malware/dnschanger.md)|November 2011|--|Alters DNS server settings to route to a rogue DNS server for the purpose of click hijacking. [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Performs click-fraud. [[3]](#3)| -|[**YiSpecter**](../xample-malware/yispecter.md)|2015|E1643.m02|Displays brief advertisements whenever the user opens applications on their phone [[4]](#4)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|E1643.m02|Malware alters DNS server settings to route to a rogue DNS server for the purpose of click hijacking. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter performs click-fraud. [[4]](#4)| +|[**YiSpecter**](../xample-malware/yispecter.md)|2015|E1643.m02|The malware displays brief advertisements whenever the user opens applications on their phone. [[5]](#5)| + ## References @@ -62,4 +63,3 @@ Malware may generate traffic from the victim system such as clicks of advertisin [5] https://blog.malwarebytes.com/threat-analysis/2016/07/untangling-kovter/ [6] https://www.huffingtonpost.com/2011/11/09/click-hijack-hackers-online-ad-scam_n_1084497.html - diff --git a/impact/manipulate-network-traffic.md b/impact/manipulate-network-traffic.md index 9184774..7625d3a 100644 --- a/impact/manipulate-network-traffic.md +++ b/impact/manipulate-network-traffic.md @@ -32,7 +32,7 @@ # Manipulate Network Traffic -Malware intercepts and manipulates network traffic, typically accessing or modifying data, going to or originating from the system on which the malware instance is executing. Also known as a Man-in-the-Middle attack. +Malware intercepts and manipulates network traffic, typically accessing or modifying data, going to or originating from the system on which the malware instance is executing, also known as a Man-in-the-Middle attack. The related **Data Manipulation: Transmitted Data Manipulation ([T1565.002](https://attack.mitre.org/techniques/T1565/002/))** ATT&CK sub-technique was defined subsequent to this MBC behavior. @@ -40,12 +40,12 @@ The related **Data Manipulation: Transmitted Data Manipulation ([T1565.002](http |Name|Date|Method|Description| |---|---|---|---| -|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|--|Intercepts encrypted web traffic to inject adds. [[1]](#1)| -|[**MazarBot**](../xample-malware/mazarbot.md)|2016|--|Intercepts data coming into and going out of device. [[2]](#2)| +|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|--|SearchAwesome adware intercepts encrypted web traffic to inject ads. [[1]](#1)| +|[**MazarBot**](../xample-malware/mazarbot.md)|2016|--|MazarBot intercepts data coming into and going out of the device. [[2]](#2)| + ## References [1] https://blog.malwarebytes.com/threat-analysis/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection/ [2] https://us.norton.com/internetsecurity-emerging-threats-mazar-bot-malware-invades-and-erases-android-devices.html - diff --git a/impact/remote-access.md b/impact/remote-access.md index d5d275b..2eb84ad 100644 --- a/impact/remote-access.md +++ b/impact/remote-access.md @@ -48,9 +48,10 @@ Note that the **Ingress Tool Transfer ([T1105](https://attack.mitre.org/techniqu |Name|Date|Method|Description| |---|---|---|---| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|--|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[2]](#2)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Allows an attacker to control the system via a GUI [[3]](#3)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|The malware acts as a backdoor [[4]](#4)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|After the Poison Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[2]](#2)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Dark Comet allows an attacker to control the system via a GUI. [[3]](#3)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|The malware acts as a backdoor. [[4]](#4)| + ## References @@ -62,5 +63,3 @@ Note that the **Ingress Tool Transfer ([T1105](https://attack.mitre.org/techniqu [4] https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/HUPIGON -[5] https://www.cyber.nj.gov/threat-center/threat-profiles/trojan-variants/poison-ivy - diff --git a/impact/resource-hijacking.md b/impact/resource-hijacking.md index b475859..dad4eb2 100644 --- a/impact/resource-hijacking.md +++ b/impact/resource-hijacking.md @@ -32,7 +32,7 @@ # Resource Hijacking -Uses system resources for other purposes; as a result, the system may not be available for intended uses. +Malware uses system resources for other purposes; as a result, the system may not be available for intended uses. The related **Resource Hijacking ([T1496](https://attack.mitre.org/techniques/T1496/))** ATT&CK technique was defined subsequent to this MBC behavior. @@ -47,10 +47,11 @@ The related **Resource Hijacking ([T1496](https://attack.mitre.org/techniques/T1 |Name|Date|Method|Description| |---|---|---|---| -|[**WebCobra**](../xample-malware/webcobra.md)|2018|--|Drops software to mine for cryptocurrency. [[1]](#1)| -|**Adylkuzz**|May 2017|--|Consumes system resources to mine for cryptocurrency. [[2]](#2)| +|[**WebCobra**](../xample-malware/webcobra.md)|2018|B0018.002|The malware drops software that mines for cryptocurrency, depending on the system architecture. If the system has x86 architecture, the malware drops Cryptonight miner. If the system has x64 architecture, the malware drops Claymore's Zcash miner. [[1]](#1)| +|[**Adylkuzz**]|2017|--|Malware consumes system resources to mine for cryptocurrency. [[2]](#2)| |[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR can use the compromised computer’s network bandwidth to seed torrents or execute DDoS. [[3]](#3)| -|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer uses sytem resources to mine for cryptocurrency [[4]](#4)| +|[**Clipminer**](../xample-malware/clipminer.md)|2011|--|Clipminer uses sytem resources to mine for cryptocurrency. [[4]](#4)| + ## References diff --git a/impact/spamming.md b/impact/spamming.md index 0a1faf6..62e2bcb 100644 --- a/impact/spamming.md +++ b/impact/spamming.md @@ -38,7 +38,7 @@ Malware may use a victim machine to create and send spam. |Name|Date|Method|Description| |---|---|---|---| -|[**TrickBot**](../xample-malware/trickbot.md)|2019|--|TrickBot was observed infecting computers to steal email passwords and address books to spread malicious emails. [[1]](#1)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|In July 2019, TrickBot was observed infecting computers to steal email passwords and address books to spread malicious emails. [[1]](#1)| |[**Gamut**](../xample-malware/gamut.md)|2014|--|If port 25 is open, the bot uses a spam template and email list to send spam. [[2]](#2)| ## References diff --git a/lateral-movement/supply-chain-compromise.md b/lateral-movement/supply-chain-compromise.md index c04acaa..54b6a6c 100644 --- a/lateral-movement/supply-chain-compromise.md +++ b/lateral-movement/supply-chain-compromise.md @@ -28,7 +28,7 @@ # Supply Chain Compromise -The supply chain may be compromised to enable initial malware infection. MBC objectives don't encompass initial infection, but the malware-related methods are listed below supplement the information available defined in ATT&CK and allow for lateral movement: **Supply Chain Compromise ([T1195](https://attack.mitre.org/techniques/T1195/), [T1474](https://attack.mitre.org/techniques/T1474/))**. +The supply chain may be compromised to enable initial malware infection. MBC objectives don't encompass initial infection, but the malware-related methods listed below supplement the information available and defined in ATT&CK and allow for lateral movement: **Supply Chain Compromise ([T1195](https://attack.mitre.org/techniques/T1195/), [T1474](https://attack.mitre.org/techniques/T1474/))**. ## Methods @@ -41,9 +41,14 @@ The supply chain may be compromised to enable initial malware infection. MBC obj |Name|Date|Method|Description| |---|---|---|---| -|[**YiSpecter**](../xample-malware/yispecter.md)|October 2015|E1195.m02, E1195.m01|Please see the YiSpecter malware page for details. [[1]](#1)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|TrickBot comes with a signed downloader component. [[2]](#2)| +|[**YiSpecter**](../xample-malware/yispecter.md)|2015|E1195.m01|YiSpecter's malicious apps were signed with three iOS enterprise certificates issued by Apple so they can be installed as enterprise apps on non-jailbroken iOS devices via in-house distribution. [[1]](#1)| +|[**YiSpecter**](../xample-malware/yispecter.md)|2015|E1195.m02|Within the malware, use of the private API allows installation of malicious apps and uninstallation of legitimate apps without user notification. [[1]](#1)| + ## References [1] http://researchcenter.paloaltonetworks.com/2015/10/yispecter-first-ios-malware-attacks-non-jailbroken-ios-devices-by-abusing-private-apis/ +[2] https://eclypsium.com/wp-content/uploads/2020/12/TrickBot-Now-Offers-TrickBoot-Persist-Brick-Profit.pdf + diff --git a/micro-behaviors/communication/dns-communication.md b/micro-behaviors/communication/dns-communication.md index be6c112..170f84e 100644 --- a/micro-behaviors/communication/dns-communication.md +++ b/micro-behaviors/communication/dns-communication.md @@ -44,8 +44,8 @@ The DNS Communication micro-behavior focuses on DNS communication. |Name|Date|Method|Description| |---|---|---|---| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0011.001|Resolve DNS (This capa rule had 1 match) [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|C0011.001|Resolve DNS (This capa rule had 1 match) [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0011.001|Hupigon resolves DNS. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|C0011.001|Shamoon resolves DNS. [[1]](#1)| ## References diff --git a/micro-behaviors/communication/http-communication.md b/micro-behaviors/communication/http-communication.md index afd3895..2751858 100644 --- a/micro-behaviors/communication/http-communication.md +++ b/micro-behaviors/communication/http-communication.md @@ -53,17 +53,20 @@ Instead of being listed alphabetically, methods have been grouped to better faci |**Read Header**|C0002.014|HTTP read header.| |**IWebBrowser**|C0002.010|The IWebBrowser interface exposes methods and properties implemented by the WebBrowser control or implemented by an instance of the InternetExplorer application. Specific methods and properties can be captured: e.g., COMMUNICATION::HTTP Communication::IWebBrowser.get_Document.| |**WinHTTP**|C0002.008|An HTTP request is made via the Windows HTTP Services (WinHTTP) application programming interface (API).| -|**WinINet**|C0002.007|A HTTP request is made via the Windows Internet (WinINet) application programming interface (API). A specific function can be specified as a method on the [WinInet](../communication/wininet.md) microbehavior.| +|**WinINet**|C0002.007|A HTTP request is made via the Windows Internet (WinINet) application programming interface (API). A specific function can be specified as a method on the [WinInet](../communication/wininet.md) micro-behavior.| + ## Use in Malware |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0002.011, C0002.010|Please see the BlackEnergy malware page for details. [[1]](#1)| -|[**Emotet**](../xample-malware/emotet.md)|2018|C0002.012|Create http request (this capa rule had 1 match) [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|C0002.009, C0002.012|Please see the Kovter malware page for details. [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0002.010|The malware initializes IWebBrowser2. [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0002.011|The malware extracts the HTTP body. [[1]](#1)| +|[**Emotet**](../xample-malware/emotet.md)|2018|C0002.012|The malware creates a HTTP request. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|C0002.009|Kovter connects to a HTTP server. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|C0002.012|Kovter creates a HTTP request. [[1]](#1)| + ## References [1] capa v4.0, analyzed at MITRE on 10/12/2022 - diff --git a/micro-behaviors/communication/interprocess-communication.md b/micro-behaviors/communication/interprocess-communication.md index ca9e571..96a5e08 100644 --- a/micro-behaviors/communication/interprocess-communication.md +++ b/micro-behaviors/communication/interprocess-communication.md @@ -44,7 +44,7 @@ The Interprocess Communication micro-behavior focuses on interprocess communicat |Name|Date|Method|Description| |---|---|---|---| |[**Hupigon**](../xample-malware/hupigon.md)|2013|C0003.001, C0003.004|Please see the Hupigon malware page for details. [[1]](#1)| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|C0003.004|Write pipe (This capa rule had 1 match) [[1]](#1)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|C0003.004|Poison Ivy writes pipes. [[1]](#1)| ## References diff --git a/micro-behaviors/communication/smtp-communication.md b/micro-behaviors/communication/smtp-communication.md index 16f0931..33a4c10 100644 --- a/micro-behaviors/communication/smtp-communication.md +++ b/micro-behaviors/communication/smtp-communication.md @@ -35,4 +35,4 @@ This micro-behavior focuses on SMTP communication. |Name|ID|Description| |---|---|---| |**Request**|C0012.002|Makes SMTP request.| -|**Server Connect**|C0012.001|Connects to an smtp server.| +|**Server Connect**|C0012.001|Connects to an SMTP server.| diff --git a/micro-behaviors/communication/socket-communication.md b/micro-behaviors/communication/socket-communication.md index 156dbda..4065791 100644 --- a/micro-behaviors/communication/socket-communication.md +++ b/micro-behaviors/communication/socket-communication.md @@ -59,10 +59,11 @@ Instead of being listed alphabetically, methods have been grouped to better faci |Name|Date|Method|Description| |---|---|---|---| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0001.010|Create UDP socket (This capa rule had 1 match) [[2]](#2)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0001.011|Create TCP socket (This capa rule had 1 match) [[2]](#2)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|C0001.009|Initialize Winsock library (This capa rule had 1 match) [[2]](#2)| -|[**SYNful Knock**](../xample-malware/synful-knock.md)|2015|C0001.014|To initiate communication with the C2 server, a uniquely crafted TCP SYN packet is sent to port 80 of the "implanted" router [[1]](#1)| +|[**SYNful Knock**](../../xample-malware/synful-knock.md)|2015|C0001.014|SYNful Knock initiates communication with the C2 server via a uniquely crafted TCP SYN packet sent to port 80 of the "implanted" router. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0001.010|Hupigon creates a UDP socket. [[2]](#2)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0001.011|Rombertik creates a TCP socket. [[2]](#2)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|C0001.009|Shamoon initializes a Winsock library. [[2]](#2)| + ## References diff --git a/micro-behaviors/cryptography/cryptographic-hash.md b/micro-behaviors/cryptography/cryptographic-hash.md index 2b332b8..f08eca0 100644 --- a/micro-behaviors/cryptography/cryptographic-hash.md +++ b/micro-behaviors/cryptography/cryptographic-hash.md @@ -45,10 +45,13 @@ Malware may use a cryptographic hash. |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0029, C0029.001, C0029.002|Please see the BlackEnergy malware page for details. [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Hash data via WinCrypt (This capa rule had 22 matches) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|C0029, C0029.002|Please see the Redhip malware page for details. [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|C0029.002|Hash data using SHA1 (This capa rule had 1 match) [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy hashes data via WinCrypt. [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0029.001|BlackEnergy hashes data with MD5. [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0029.002|BlackEnergy hashes data using SHA1. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter hashes data via WinCrypt. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip hashes data via WinCrypt. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|C0029.002|Redhip hashes data using SHA1. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|C0029.002|UP007 hashes data using SHA1. [[1]](#1)| ## References diff --git a/micro-behaviors/cryptography/decrypt-data.md b/micro-behaviors/cryptography/decrypt-data.md index b9bf875..f8f544d 100644 --- a/micro-behaviors/cryptography/decrypt-data.md +++ b/micro-behaviors/cryptography/decrypt-data.md @@ -54,7 +54,7 @@ Malware may decrypt data. |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Encrypt or decrypt via WinCrypt (This capa rule had 1 match) [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy encrypts or decrypts via WinCrypt. [[1]](#1)| |[**Kovter**](../xample-malware/kovter.md)|2016|--|Encrypt or decrypt via WinCrypt (This capa rule had 1 match) [[1]](#1)| ## Code Snippets diff --git a/micro-behaviors/cryptography/encrypt-data.md b/micro-behaviors/cryptography/encrypt-data.md index 5646ac5..2db72eb 100644 --- a/micro-behaviors/cryptography/encrypt-data.md +++ b/micro-behaviors/cryptography/encrypt-data.md @@ -54,19 +54,22 @@ Malware may encrypt data. |Name|Date|Method|Description| |---|---|---|---| -|[**TrickBot**](../../xample-malware/trickbot.md)|2016|C0027.001|Uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files [[1]](#1)| -|[**GravityRAT**](../../xample-malware/gravity-rat.md)|2018|C0027.001| GravityRat v3 supports file AES file encryption [[3]](#3)| -|[**Poison-Ivy**](../../xample-malware/poison-ivy.md)|2005|C0027.003|Poison Ivy's custom network protocol over TCP is encrypted using Camellia cipher with a 256-bit key [[4]](#4)| -|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|C0027.009|CHOPSTICK encrypts the configuration block using RC4 encryption [[5]](#5)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0027.009|Encrypt data using RC4 via WinAPI (This capa rule had 1 match) [[6]](#6)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0027.009|Encrypt data using RC4 PRGA (This capa rule had 3 matches) [[6]](#6)| -|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|C0027.009|Encrypt data using RC4 PRGA (This capa rule had 1 match) [[6]](#6)| -|[**Emotet**](../xample-malware/emotet.md)|2018|C0027.011, C0027.009|Please see the Emotet malware page for details. [[2]](#2)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0027.004|Encrypt data using DES (This capa rule had 1 match) [[6]](#6)| -|[**Kraken**](../xample-malware/kraken.md)|2008|C0027.009|Encrypt data using RC4 PRGA (This capa rule had 2 matches) [[6]](#6)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|C0027.009|Encrypt data using RC4 PRGA (This capa rule had 1 match) [[6]](#6)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Encrypt data using DPAPI (This capa rule had 6 matches) [[6]](#6)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0027.009|Encrypt data using RC4 PRGA (This capa rule had 1 match) [[6]](#6)| +|[**TrickBot**](../../xample-malware/trickbot.md)|2016|C0027.001|The malware uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files. [[1]](#1)| +|[**Emotet**](../xample-malware/emotet.md)|2018|C0027.009|Emotet encrypts data using RC4 PRGA. [[8]](#8)| +|[**Emotet**](../../xample-malware/emotet.md)|2018|C0027.011|Emotet uses RSA to encrypt network traffic to its C2. [[2]](#2)| +|[**GravityRAT**](../../xample-malware/gravity-rat.md)|2018|C0027.001|GravityRat v3 supports file AES file encryption. [[3]](#3)| +|[**Poison Ivy**](../../xample-malware/poison-ivy.md)|2005|C0027.003|Poison Ivy's custom network protocol over TCP is encrypted using Camellia cipher with a 256-bit key. [[4]](#4)| +|[**CHOPSTICK**](../xample-malware/chopstick.md)|2015|C0027.009|CHOPSTICK encrypts the configuration block using RC4 encryption. [[5]](#5)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|C0027.009|The malware decrypts inner configurations stored in the binary. The malware also encrypts the value of each JSON key with RC4 and encodes the value with Base64. [[6]](#6) [[7]](#7)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0027.009|BlackEnergy encrypts data using RC4 via WinAPI. [[8]](#8)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0027.009|Dark Comet encrypts data using RC4 PRGA. [[8]](#8)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|C0027.009|DNSChanger encrypts data using RC4 PRGA. [[8]](#8)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0027.004|Hupigon encrypts data using DES. [[8]](#8)| +|[**Kraken**](../xample-malware/kraken.md)|2008|C0027.009|Kraken encrypts data using RC4 PRGA. [[8]](#8)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|C0027.009|Locky Bart encrypts data using RC4 PRGA. [[8]](#8)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip encrypts data using DPAPI. [[8]](#8)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0027.009|Rombertik encrypts data using RC4 PRGA. [[8]](#8)| + ## Code Snippets @@ -139,5 +142,8 @@ retn [5] https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf -[6] capa v4.0, analyzed at MITRE on 10/12/2022 +[6] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ +[7] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader + +[8] capa v4.0, analyzed at MITRE on 10/12/2022 diff --git a/micro-behaviors/cryptography/encryption-key.md b/micro-behaviors/cryptography/encryption-key.md index d7537da..63a3687 100644 --- a/micro-behaviors/cryptography/encryption-key.md +++ b/micro-behaviors/cryptography/encryption-key.md @@ -30,6 +30,7 @@ Malware may import, generate, or otherwise use an encryption key. + ## Methods |Name|ID|Description| @@ -37,14 +38,16 @@ Malware may import, generate, or otherwise use an encryption key. |**Import Public Key**|C0028.001|Malware imports a public key.| |**RC4 KSA**|C0028.002|Malware uses the RC4 Key Scheduling Algorithm (KSA).| + ## Use in Malware |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Create new key via CryptAcquireContext (This capa rule had 1 match) [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Create new key via CryptAcquireContext (This capa rule had 1 match) [[1]](#1)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Create new key via CryptAcquireContext (This capa rule had 1 match) [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0028.002|Encrypt data using RC4 KSA (This capa rule had 1 match) [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy creates new key via CryptAcquireContext. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter creates a new key via CryptAcquireContext. [[1]](#1)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Locky Bart creates a new key via CryptAcquireContext. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0028.002|Rombertik encrypts data using RC4 KSA. [[1]](#1)| + ## References diff --git a/micro-behaviors/cryptography/generate-pseudorandom-sequence.md b/micro-behaviors/cryptography/generate-pseudorandom-sequence.md index bd37e3a..88db49d 100644 --- a/micro-behaviors/cryptography/generate-pseudorandom-sequence.md +++ b/micro-behaviors/cryptography/generate-pseudorandom-sequence.md @@ -28,7 +28,7 @@ # Generate Pseudo-random Sequence -The Generate Pseudo-random Sequence microbehavior can be used for a number of purposes. The methods below include specific functions, as well as pseudorandom number generators (PRNG). +The Generate Pseudo-random Sequence micro-behavior can be used for a number of purposes. The methods below include specific functions, as well as pseudo-random number generators (PRNG). ## Methods @@ -43,7 +43,7 @@ The Generate Pseudo-random Sequence microbehavior can be used for a number of pu |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0021.003|Generate random numbers via WinAPI (This capa rule had 1 match) [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0021.003|BlackEnergy generates random numbers via WinAPI. [[1]](#1)| |[**Locky Bart**](../xample-malware/locky-bart.md)|2017|C0021.003|Generate random numbers via WinAPI (This capa rule had 1 match) [[1]](#1)| ## References diff --git a/micro-behaviors/data/check-string.md b/micro-behaviors/data/check-string.md index f7163b1..dfef29e 100644 --- a/micro-behaviors/data/check-string.md +++ b/micro-behaviors/data/check-string.md @@ -28,15 +28,16 @@ # Check String -Malware may check a string for some characteristics, such as being ascii content; credit card number; or length. +Malware may check a string for some characteristics, such as being ASCII content, credit card number, or length. + ## Use in Malware |Name|Date|Method|Description| |---|---|---|---| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Reference Base64 string (This capa rule had 1 match) [[1]](#1)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Locky Bart references Base64 strings. [[1]](#1)| + ## References [1] capa v4.0, analyzed at MITRE on 10/12/2022 - diff --git a/micro-behaviors/data/checksum.md b/micro-behaviors/data/checksum.md index 65a40ef..549bcc2 100644 --- a/micro-behaviors/data/checksum.md +++ b/micro-behaviors/data/checksum.md @@ -30,6 +30,7 @@ Malware may derive a checksum from some block of data. The checksum is often used for data validation. + ## Methods |Name|ID|Description| @@ -39,14 +40,16 @@ Malware may derive a checksum from some block of data. The checksum is often use |**CRC32**|C0032.001|Malware computes a CRC32 checksum.| |**Luhn**|C0032.002|Malware uses Luhn algorithm, often to validate identification numbers (e.g, credit card number).| + ## Use in Malware |Name|Date|Method|Description| |---|---|---|---| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0032.001|Hash data with CRC32 (This capa rule had 5 matches) [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|C0032.001|Hash data with CRC32 (This capa rule had 1 match) [[1]](#1)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|C0032.001|Hash data with CRC32 (This capa rule had 2 matches) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|C0032.001|Hash data with CRC32 (This capa rule had 1 match) [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0032.001|Dark Comet hashes data with CRC32. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|C0032.001|Gamut hashes data with CRC32. [[1]](#1)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|C0032.001|Locky Bart hashes data with CRC32. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|C0032.001|UP007 hashes data with CRC32. [[1]](#1)| + ## References diff --git a/micro-behaviors/data/compression-library.md b/micro-behaviors/data/compression-library.md index fc9e73c..f8b4e2d 100644 --- a/micro-behaviors/data/compression-library.md +++ b/micro-behaviors/data/compression-library.md @@ -33,7 +33,7 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Linked against ZLIB (This capa rule had 1 match) [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|DarkComet linked against ZLIB. [[1]](#1)| |[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Linked against ZLIB (This capa rule had 1 match) [[1]](#1)| ## References diff --git a/micro-behaviors/data/decode-data.md b/micro-behaviors/data/decode-data.md index 3575d6a..ffe4573 100644 --- a/micro-behaviors/data/decode-data.md +++ b/micro-behaviors/data/decode-data.md @@ -34,5 +34,5 @@ Malware may decode data. |Name|ID|Description| |---|---|---| -|**Base64**|C0053.001|Malware may decode data using Base64.| -|**XOR**|C0053.002|Malware may use xor to decode data.| +|**Base64**|C0053.001|Malware may decode data using base64.| +|**XOR**|C0053.002|Malware may use XOR to decode data.| diff --git a/micro-behaviors/data/decompress-data.md b/micro-behaviors/data/decompress-data.md index 9d67e5c..b04cfcb 100644 --- a/micro-behaviors/data/decompress-data.md +++ b/micro-behaviors/data/decompress-data.md @@ -42,7 +42,7 @@ Malware may decompress data. |Name|Date|Method|Description| |---|---|---|---| -|[**Bagle**](../xample-malware/bagle.md)|2004|C0025.003|Decompress data using aPLib (This capa rule had 1 match) [[1]](#1)| +|[**Bagle**](../xample-malware/bagle.md)|2004|C0025.003|Bagle decompresses data using aPLib. [[1]](#1)| ## References diff --git a/micro-behaviors/data/encode-data.md b/micro-behaviors/data/encode-data.md index ef4a4bd..d0de1b0 100644 --- a/micro-behaviors/data/encode-data.md +++ b/micro-behaviors/data/encode-data.md @@ -35,28 +35,28 @@ Malware may encode data. |Name|ID|Description| |---|---|---| |**Base64**|C0026.001|Malware may encode data using Base64.| -|**XOR**|C0026.002|Malware may use xor to encode data.| +|**XOR**|C0026.002|Malware may use XOR to encode data.| + ## Use in Malware |Name|Date|Method|Description| |---|---|---|---| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|C0026.002|Encode data using XOR (This capa rule had 1 match) [[1]](#1)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0026.002|Encode data using XOR (This capa rule had 13 matches) [[1]](#1)| -|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|C0026.002|Encode data using XOR (This capa rule had 1 match) [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|C0026.002|Encode data using XOR (This capa rule had 1 match) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0026.002|Encode data using XOR (This capa rule had 8 matches) [[1]](#1)| -|[**Kraken**](../xample-malware/kraken.md)|2008|C0026.002|Encode data using XOR (This capa rule had 2 matches) [[1]](#1)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|C0026.002|Encode data using XOR (This capa rule had 4 matches) [[1]](#1)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|C0026.002|Encode data using XOR (This capa rule had 2 matches) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|C0026.002|Encode data using XOR (This capa rule had 1 match) [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0026.002|Encode data using XOR (This capa rule had 5 matches) [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|C0026.002|Encode data using XOR (This capa rule had 1 match) [[1]](#1)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|C0026.002|Encode data using XOR (This capa rule had 3 matches) [[1]](#1)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|C0026.002|Encode data using XOR (This capa rule had 2 matches) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|C0026.002|Encode data using XOR (This capa rule had 13 matches) [[1]](#1)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|C0026.002|CryptoLocker encodes data using XOR. [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0026.002|Dark Comet encodes data using XOR. [[1]](#1)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|C0026.002|DNSChanger encodes data using XOR. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|C0026.002|Gamut encodes data using XOR. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0026.002|Hupigon encodes data using XOR. [[1]](#1)| +|[**Kraken**](../xample-malware/kraken.md)|2008|C0026.002|Kraken encodes data using XOR. [[1]](#1)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|C0026.002|Locky Bart encodes data using XOR. [[1]](#1)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|C0026.002|Mebromi encodes data using XOR. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|C0026.002|Redhip encodes data using XOR. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0026.002|Rombertik encodes data using XOR. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|C0026.002|Shamoon encodes data using XOR. [[1]](#1)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|C0026.002|Stuxnet encodes data using XOR. [[1]](#1)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|C0026.002|TrickBot encodes data using XOR. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|C0026.002|The malware encodes data using XOR. [[1]](#1)| ## References [1] capa v4.0, analyzed at MITRE on 10/12/2022 - diff --git a/micro-behaviors/data/use-constant.md b/micro-behaviors/data/use-constant.md index 38bd889..5c5276c 100644 --- a/micro-behaviors/data/use-constant.md +++ b/micro-behaviors/data/use-constant.md @@ -28,4 +28,4 @@ # Use Constant -Malware may manipulate or use a constant value, for example as part of a larger string used by some function. +Malware may manipulate or use a constant value; for example, as part of a larger string used by some function. diff --git a/micro-behaviors/file-system/copy-file.md b/micro-behaviors/file-system/copy-file.md index 5966e2d..0c7b97d 100644 --- a/micro-behaviors/file-system/copy-file.md +++ b/micro-behaviors/file-system/copy-file.md @@ -33,12 +33,12 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|Copy file (This capa rule had 1 match) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Copy file (This capa rule had 1 match) [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Copy file (This capa rule had 5 matches) [[1]](#1)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Copy file (This capa rule had 2 matches) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Copy file (This capa rule had 2 matches) [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Copy file (This capa rule had 2 matches) [[1]](#1)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR copies files. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon copies files. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter copies files. [[1]](#1)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Mebromi copies files. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip copies files. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon copies files. [[1]](#1)| ## References diff --git a/micro-behaviors/file-system/create-directory.md b/micro-behaviors/file-system/create-directory.md index 7d8eedc..85aeb08 100644 --- a/micro-behaviors/file-system/create-directory.md +++ b/micro-behaviors/file-system/create-directory.md @@ -33,13 +33,13 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Create directory (This capa rule had 1 match) [[1]](#1)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|Create directory (This capa rule had 1 match) [[1]](#1)| -|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|Create directory (This capa rule had 1 match) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Create directory (This capa rule had 1 match) [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Create directory (This capa rule had 14 matches) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Create directory (This capa rule had 1 match) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Create directory (This capa rule had 1 match) [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut creates directories. [[1]](#1)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR creates directories. [[1]](#1)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|GravityRAT creates directories. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon creates directories. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter creates directories. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip creates directories. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|--|UP007 creates directories. [[1]](#1)| ## References diff --git a/micro-behaviors/file-system/delete-directory.md b/micro-behaviors/file-system/delete-directory.md index 6826620..b7581f3 100644 --- a/micro-behaviors/file-system/delete-directory.md +++ b/micro-behaviors/file-system/delete-directory.md @@ -33,7 +33,7 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Delete directory (This capa rule had 1 match) [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut deletes directories. [[1]](#1)| |[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Delete directory (This capa rule had 1 match) [[1]](#1)| |[**Kovter**](../xample-malware/kovter.md)|2016|--|Delete directory (This capa rule had 4 matches) [[1]](#1)| diff --git a/micro-behaviors/file-system/delete-file.md b/micro-behaviors/file-system/delete-file.md index 9492201..98ed28a 100644 --- a/micro-behaviors/file-system/delete-file.md +++ b/micro-behaviors/file-system/delete-file.md @@ -33,19 +33,19 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Delete file (This capa rule had 1 match) [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Delete file (This capa rule had 4 matches) [[1]](#1)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|Delete file (This capa rule had 1 match) [[1]](#1)| -|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|Delete file (This capa rule had 1 match) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Delete file (This capa rule had 1 match) [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Delete file (This capa rule had 2 matches) [[1]](#1)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Delete file (This capa rule had 5 matches) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Delete file (This capa rule had 2 matches) [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Delete file (This capa rule had 1 match) [[1]](#1)| -|[**SamSam**](../xample-malware/samsam.md)|2015|--|Delete file (This capa rule had 1 match) [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Delete file (This capa rule had 6 matches) [[1]](#1)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Delete file (This capa rule had 1 match) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Delete file (This capa rule had 2 matches) [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Dark Comet deletes files. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut deletes files. [[1]](#1)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR deletes files. [[1]](#1)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|GravityRAT deletes files. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon deletes files. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter deletes files. [[1]](#1)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Mebromi deletes files. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip deletes files. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Rombertik deletes files. [[1]](#1)| +|[**SamSam**](../xample-malware/samsam.md)|2015|--|SamSam deletes files. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon deletes files. [[1]](#1)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Stuxnet deletes files. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|--|UP007 deletes files. [[1]](#1)| ## References diff --git a/micro-behaviors/file-system/get-file-attributes.md b/micro-behaviors/file-system/get-file-attributes.md index 87e0c7a..c1f5e7a 100644 --- a/micro-behaviors/file-system/get-file-attributes.md +++ b/micro-behaviors/file-system/get-file-attributes.md @@ -33,12 +33,12 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Get file attributes (This capa rule had 2 matches) [[1]](#1)| -|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|Get file attributes (This capa rule had 1 match) [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Get file attributes (This capa rule had 10 matches) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Get file attributes (This capa rule had 3 matches) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Get file attributes (This capa rule had 2 matches) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Get file attributes (This capa rule had 7 matches) [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Dark Comet gets file attributes. [[1]](#1)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|DNSChanger gets file attributes. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut gets file attributes. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon gets file attributes. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip gets file attributes. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|--|UP007 gets file attributes. [[1]](#1)| ## References diff --git a/micro-behaviors/file-system/move-file.md b/micro-behaviors/file-system/move-file.md index 09857e0..09a361e 100644 --- a/micro-behaviors/file-system/move-file.md +++ b/micro-behaviors/file-system/move-file.md @@ -33,12 +33,12 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Move file (This capa rule had 1 match) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Move file (This capa rule had 1 match) [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Move file (This capa rule had 24 matches) [[1]](#1)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Move file (This capa rule had 2 matches) [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Move file (This capa rule had 2 matches) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Move file (This capa rule had 2 matches) [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut moves files. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon moves files. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter moves files. [[1]](#1)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Mebromi moves files. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon moves files. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|--|UP007 moves files. [[1]](#1)| ## References diff --git a/micro-behaviors/file-system/read-file.md b/micro-behaviors/file-system/read-file.md index e798c7b..630273e 100644 --- a/micro-behaviors/file-system/read-file.md +++ b/micro-behaviors/file-system/read-file.md @@ -33,20 +33,20 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Read file on Windows (This capa rule had 7 matches) [[1]](#1)| -|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|Read file on Windows (This capa rule had 3 matches) [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Read file on Windows (This capa rule had 2 matches) [[1]](#1)| -|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|Read file on Windows (This capa rule had 9 matches) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Read file on Windows (This capa rule had 1 match) [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Read file on Windows (This capa rule had 4 matches) [[1]](#1)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Read file on Windows (This capa rule had 2 matches) [[1]](#1)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Read file on Windows (This capa rule had 1 match) [[1]](#1)| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|--|Read file on Windows (This capa rule had 1 match) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Read file on Windows (This capa rule had 3 matches) [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Read file on Windows (This capa rule had 3 matches) [[1]](#1)| -|[**SamSam**](../xample-malware/samsam.md)|2015|--|Read file on Windows (This capa rule had 1 match) [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Read file on Windows (This capa rule had 1 match) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Read file on Windows (This capa rule had 1 match) [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Dark Comet reads files on Windows. [[1]](#1)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|DNSChanger reads files on Windows. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut reads files on Windows. [[1]](#1)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|GravityRAT reads files on Windows. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon reads files on Windows. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter reads files on Windows. [[1]](#1)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Locky Bart reads files on Windows. [[1]](#1)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Mebromi reads files on Windows. [[1]](#1)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy reads files on Windows. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip reads files on Windows. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Rombertik reads files on Windows. [[1]](#1)| +|[**SamSam**](../xample-malware/samsam.md)|2015|--|SamSam reads files on Windows. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon reads files on Windows. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|--|UP007 reads files on Windows. [[1]](#1)| ## References diff --git a/micro-behaviors/file-system/set-file-attributes.md b/micro-behaviors/file-system/set-file-attributes.md index bfca52c..73cb327 100644 --- a/micro-behaviors/file-system/set-file-attributes.md +++ b/micro-behaviors/file-system/set-file-attributes.md @@ -33,12 +33,12 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|Set file attributes (This capa rule had 1 match) [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Set file attributes (This capa rule had 2 matches) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Set file attributes (This capa rule had 1 match) [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Set file attributes (This capa rule had 3 matches) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Set file attributes (This capa rule had 1 match) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Set file attributes (This capa rule had 4 matches) [[1]](#1)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|DNSChanger sets file attributes. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut sets file attributes. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon sets file attributes. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter sets file attributes. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip sets file attributes. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|--|UP007 sets file attributes. [[1]](#1)| ## References diff --git a/micro-behaviors/file-system/writes-file.md b/micro-behaviors/file-system/writes-file.md index ffaafc3..8098f11 100644 --- a/micro-behaviors/file-system/writes-file.md +++ b/micro-behaviors/file-system/writes-file.md @@ -33,18 +33,18 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|Writes Fileon Windows (This capa rule had 1 match) [[1]](#1)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Writes Fileon Windows (This capa rule had 5 matches) [[1]](#1)| -|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|Writes Fileon Windows (This capa rule had 2 matches) [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Writes file on Windows (This capa rule had 3 matches) [[1]](#1)| -|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|Write file on Windows (This capa rule had 7 matches) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Write file on Windows (This capa rule had 4 matches) [[1]](#1)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Write file on Windows (This capa rule had 3 matches) [[1]](#1)| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|--|Write file on Windows (This capa rule had 1 match) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Write file on Windows (This capa rule had 1 match) [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Write file on Windows (This capa rule had 4 matches) [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Write file on Windows (This capa rule had 1 match) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Write file on Windows (This capa rule had 1 match) [[1]](#1)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|CryptoLocker writes Fileon Windows. [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Dark Comet writes Fileon Windows. [[1]](#1)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|DNSChanger writes Fileon Windows. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut writes files on Windows. [[1]](#1)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|GravityRAT writes files on Windows. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon writes files on Windows. [[1]](#1)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Locky Bart writes files on Windows. [[1]](#1)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy writes files on Windows. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip writes files on Windows. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Rombertik writes files on Windows. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon writes files on Windows. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|--|UP007 writes files on Windows. [[1]](#1)| ## References diff --git a/micro-behaviors/memory/allocate-memory.md b/micro-behaviors/memory/allocate-memory.md index cdb5e9d..20d733f 100644 --- a/micro-behaviors/memory/allocate-memory.md +++ b/micro-behaviors/memory/allocate-memory.md @@ -34,15 +34,15 @@ Malware allocates memory, often to unpack itself. |Name|Date|Method|Description| |---|---|---|---| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|Allocate RWX memory (This capa rule had 1 match) [[1]](#1)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Allocate RWX memory (This capa rule had 1 match) [[1]](#1)| -|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|Allocate RWX memory (This capa rule had 2 matches) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Allocate RWX memory (This capa rule had 4 matches) [[1]](#1)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Allocate RWX memory (This capa rule had 1 match) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Spawn thread to RWX shellcode (This capa rule had 1 match) [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Allocate RWX memory (This capa rule had 2 matches) [[1]](#1)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Allocate RWX memory (This capa rule had 1 match) [[1]](#1)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|Allocate RWX memory (This capa rule had 7 matches) [[1]](#1)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|CryptoLocker allocates RWX memory. [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Dark Comet allocates RWX memory. [[1]](#1)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|--|DNSChanger allocates RWX memory. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon allocates RWX memory. [[1]](#1)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Mebromi allocates RWX memory. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip spawns threads to RWX shellcode. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Rombertik allocates RWX memory. [[1]](#1)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Stuxnet allocates RWX memory. [[1]](#1)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|TrickBot allocates RWX memory. [[1]](#1)| ## References diff --git a/micro-behaviors/memory/change-memory-protection.md b/micro-behaviors/memory/change-memory-protection.md index 0314598..5770c36 100644 --- a/micro-behaviors/memory/change-memory-protection.md +++ b/micro-behaviors/memory/change-memory-protection.md @@ -28,7 +28,7 @@ # Change Memory Protection -Malware may change memory protection. For example, read-write memory may be changed to read-execute. Changing memory protection may exploits (e.g., bypass Data Execution Prevention). +Malware may change memory protection. For example, read-write memory may be changed to read-execute. Changing memory protection may allow exploits (e.g., bypass Data Execution Prevention). ## Methods @@ -42,8 +42,9 @@ Malware may change memory protection. For example, read-write memory may be chan |Name|Date|Method|Description| |---|---|---|---| -|[**Ursnif**](../../xample-malware/ursnif.md)|2016|--|Changes the PE header of the child process to enable write access to that page, writes 18 bytes of buffer at offset 0x40 from the start of svchost.exe process executable in the target child process. Then changes the region protection back to "read only" to avoid suspicion [[1]](#1)| -|[**SYNful Knock**](../xample-malware/synful-knock.md)|2015|--|Modifies the translation lookaside buffer (TLB) Read/Write attributes [[2]](#2)| +|[**Ursnif**](../../xample-malware/ursnif.md)|2016|--|The malware changes the PE header of the child process to enable write access to that page and writes 18 bytes of buffer at offset 0x40 from the start of svchost.exe in the target child process. The region protection is changed back to "read only" to avoid suspicion. [[1]](#1)| +|[**SYNful Knock**](../../xample-malware/synful-knock.md)|2015|--|SYNful Knock modifies the translation lookaside buffer (TLB) Read/Write attributes. [[2]](#2)| + ## References diff --git a/micro-behaviors/memory/overflow-buffer.md b/micro-behaviors/memory/overflow-buffer.md index b27e7de..9624f09 100644 --- a/micro-behaviors/memory/overflow-buffer.md +++ b/micro-behaviors/memory/overflow-buffer.md @@ -35,7 +35,7 @@ Malware may overflow the buffer for various purposes. |Name|Date|Method|Description| |---|---|---|---| -|[**Conficker**](../../xample-malware/conficker.md)|2008|--|Variants A, B, C, and E exploit a vulnerability in the Server Service on Windows computers in which an already compromised computer sends a specially-crafted RPC request to force a buffer overflow and execute shellcode on the target computer [[1]](#1)| +|[**Conficker**](../../xample-malware/conficker.md)|2008|--|Variants A, B, C, and E exploit a vulnerability in the Server Service on Windows computers in which an already compromised computer sends a specially-crafted RPC request to force a buffer overflow and execute shellcode on the target computer. [[1]](#1)| ## References diff --git a/micro-behaviors/operating-system/environment-variable.md b/micro-behaviors/operating-system/environment-variable.md index b18ec85..71894be 100644 --- a/micro-behaviors/operating-system/environment-variable.md +++ b/micro-behaviors/operating-system/environment-variable.md @@ -40,8 +40,8 @@ Malware modifies environment variables. |Name|Date|Method|Description| |---|---|---|---| -|[**Kovter**](../xample-malware/kovter.md)|2016|C0034.001|Set environment variable (This capa rule had 3 matches) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|C0034.001|Set environment variable (This capa rule had 1 match) [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|C0034.001|Kovter sets environment variables. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|C0034.001|UP007 sets environment variables. [[1]](#1)| ## References diff --git a/micro-behaviors/operating-system/registry.md b/micro-behaviors/operating-system/registry.md index 56859a9..8642785 100644 --- a/micro-behaviors/operating-system/registry.md +++ b/micro-behaviors/operating-system/registry.md @@ -46,19 +46,40 @@ Malware modifies the registry. |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0036.005, C0036.006|Please see the BlackEnergy malware page for details. [[1]](#1)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0036.002, C0036.007, C0036.005, C0036.006, C0036.001|Please see the Dark Comet malware page for details. [[1]](#1)| -|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|C0036.006, C0036.001|Please see the DNSChanger malware page for details. [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|C0036.002, C0036.007, C0036.005, C0036.006, C0036.001|Please see the Gamut malware page for details. [[1]](#1)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|C0036.006|Query or enumerate registry value (This capa rule had 1 match) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0036.002, C0036.007, C0036.005, C0036.006, C0036.001|Please see the Hupigon malware page for details. [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|C0036.004, C0036.006|Please see the Kovter malware page for details. [[1]](#1)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|C0036.001|Set registry value (This capa rule had 1 match) [[1]](#1)| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|C0036.006|Query or enumerate registry value (This capa rule had 1 match) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|C0036.002, C0036.006, C0036.001|Please see the Redhip malware page for details. [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0036.002, C0036.006, C0036.001|Please see the Rombertik malware page for details. [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|C0036.007, C0036.006|Please see the Shamoon malware page for details. [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|C0036.006, C0036.001|Please see the UP007 Malware Family malware page for details. [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0036.005|BlackEnergy queries or enumerates a registry key. [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|C0036.006|BlackEnergy queries or enumerates a registry value. [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0036.001|Dark Comet sets registry values. [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0036.002|Dark Comet deletes registry keys. [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0036.005|Dark Comet queries or enumerates registry keys. [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0036.006|Dark Comet queries or enumerates registry values. [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|C0036.007|Dark Comet deletes registry values. [[1]](#1)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|C0036.001|DNSChanger sets registry keys. [[1]](#1)| +|[**DNSChanger**](../xample-malware/dnschanger.md)|2011|C0036.006|DNSChanger queries or enumerates registry values. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|C0036.001|Gamut sets registry values. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|C0036.002|Gamut deletes registry keys. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|C0036.005|Gamut queries or enumerates registry keys. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|C0036.006|Gamut queries or enumerates registry values. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|C0036.007|Gamut deletes registry values. [[1]](#1)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|C0036.006|GoBotKR queries or enumerates registry values. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0036.001|Hupigon sets registry values. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0036.002|Hupigon deletes registry keys. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0036.005|Hupigon queries or enumerates registry keys. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0036.006|Hupigon queries or enumerates registry values. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|C0036.007|Hupigon deletes registry values. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|C0036.004|Kovter creates or opens registry keys. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|C0036.006|Kovter queries or enumerates registry values. [[1]](#1)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|C0036.001|Locky Bart sets registry values. [[1]](#1)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|C0036.006|Poison Ivy queries or enumerates registry values. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|C0036.001|Redhip set registry values. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|C0036.002|Redhip deletes registry keys. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|C0036.006|Redhip queries or enumerates registry values. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0036.001|Rombertik sets registry values. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0036.002|Rombertik deletes registry keys. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|C0036.006|Rombertik queries or enumerates registry values. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|C0036.006|Shamoon queries or enumerates registry values. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|C0036.007|Shamoon deletes registry values. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|C0036.001|UP007 sets registry values. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|C0036.006|UP007 queries or enumerates registry values. [[1]](#1)| ## References diff --git a/micro-behaviors/process/allocate-thread-local-storage.md b/micro-behaviors/process/allocate-thread-local-storage.md index bfb709d..033dc40 100644 --- a/micro-behaviors/process/allocate-thread-local-storage.md +++ b/micro-behaviors/process/allocate-thread-local-storage.md @@ -35,8 +35,8 @@ Malware allocates thread local storage. |Name|Date|Method|Description| |---|---|---|---| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Allocate thread local storage (This capa rule had 3 matches) [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Allocate thread local storage (This capa rule had 1 match) [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter allocates thread local storage. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon allocates thread local storage. [[1]](#1)| ## References diff --git a/micro-behaviors/process/check-mutex.md b/micro-behaviors/process/check-mutex.md index 9c0f3ea..2c20c44 100644 --- a/micro-behaviors/process/check-mutex.md +++ b/micro-behaviors/process/check-mutex.md @@ -34,11 +34,13 @@ Malware checks a mutex. |Name|Date|Method|Description| |---|---|---|---| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy variant checks if the wireshark-is-running{} named mutex object exists [[1]](#1)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy variant checks if the wireshark-is-running{} named mutex object exists. [[1]](#1)| +|[**Matanbuchus**](../xample-malware/matanbuchus.md)|2021|--|Malware checks if multiple instances of the same mutex is running. If multiple instances are running, the malware exits. [[2]](#2) [[3]](#3)| ## References [1] https://www.mandiant.com/sites/default/files/2021-09/rpt-poison-ivy.pdf -[2] https://www.fortinet.com/blog/threat-research/deep-analysis-of-new-poison-ivy-variant +[2] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ +[3] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader diff --git a/micro-behaviors/process/create-mutex.md b/micro-behaviors/process/create-mutex.md index c528fc4..b0848bf 100644 --- a/micro-behaviors/process/create-mutex.md +++ b/micro-behaviors/process/create-mutex.md @@ -34,12 +34,13 @@ Malware creates a mutex. |Name|Date|Method|Description| |---|---|---|---| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy has a default process mutex, but can be altered at build time [2] [[1]](#1)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Creates global mutexes signal that rootkit installation has occurred successfully [[2]](#2)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Create mutex (This capa rule had 1 match) [[3]](#3)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Create mutex (This capa rule had 2 matches) [[3]](#3)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Create mutex (This capa rule had 1 match) [[3]](#3)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Create mutex (This capa rule had 1 match) [[3]](#3)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|Poison Ivy has a default process mutex, but can be altered at build time. [[1]](#1)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Malware creates global mutexes that signal rootkit installation has occurred successfully. [[2]](#2)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon creates a mutex. [[3]](#3)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter creates a mutex. [[3]](#3)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip creates a mutex. [[3]](#3)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Rombertik creates a mutex. [[3]](#3)| + ## References @@ -48,6 +49,3 @@ Malware creates a mutex. [2] https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en [3] capa v4.0, analyzed at MITRE on 10/12/2022 - -[4] https://www.fortinet.com/blog/threat-research/deep-analysis-of-new-poison-ivy-variant - diff --git a/micro-behaviors/process/create-process.md b/micro-behaviors/process/create-process.md index e317a51..a6f19eb 100644 --- a/micro-behaviors/process/create-process.md +++ b/micro-behaviors/process/create-process.md @@ -43,18 +43,21 @@ Malware creates a process. |Name|Date|Method|Description| |---|---|---|---| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|C0017.002|Stuxnet will use WMI operations with the explorere.exe token in order to copy itself and exscute on the remote share [[1]](#1)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Create process on Windows (This capa rule had 2 matches) [[2]](#2)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Create process on Windows (This capa rule had 6 matches) [[2]](#2)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Create process on Windows (This capa rule had 4 matches) [[2]](#2)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|Create process on Windows (This capa rule had 4 matches) [[2]](#2)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Create process on Windows (This capa rule had 9 matches) [[2]](#2)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Create process on Windows (This capa rule had 22 matches) [[2]](#2)| -|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Create process on Windows (This capa rule had 1 match) [[2]](#2)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|C0017, C0017.003|Please see the Redhip malware page for details. [[2]](#2)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Create process on Windows (This capa rule had 2 matches) [[2]](#2)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|C0017, C0017.003|Please see the TrickBot malware page for details. [[2]](#2)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Create process on Windows (This capa rule had 3 matches) [[2]](#2)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|C0017.002|Stuxnet will use WMI operations with the explorer.exe token in order to copy itself and execute on the remote share. [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy creates a process on Windows. [[2]](#2)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Dark Comet creates a process on Windows. [[2]](#2)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut creates a process on Windows. [[2]](#2)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR creates a process on Windows. [[2]](#2)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon creates a process on Windows. [[2]](#2)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter creates a process on Windows. [[2]](#2)| +|[**Mebromi**](../xample-malware/mebromi.md)|2011|--|Mebromi creates a process on Windows. [[2]](#2)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip creates a process on Windows. [[2]](#2)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|C0017.003|Redhip creates a suspended process. [[2]](#2)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon creates a process on Windows. [[2]](#2)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|TrickBot creates a process on Windows. [[2]](#2)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|C0017.003|TrickBot creates a suspended process. [[2]](#2)| +|[**UP007**](../xample-malware/up007.md)|2016|--|The malware creates a process on Windows. [[2]](#2)| + ## References diff --git a/micro-behaviors/process/create-thread.md b/micro-behaviors/process/create-thread.md index 976a0ef..ceda669 100644 --- a/micro-behaviors/process/create-thread.md +++ b/micro-behaviors/process/create-thread.md @@ -33,12 +33,12 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Create thread (This capa rule had 3 matches) [[1]](#1)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|Create thread (This capa rule had 2 matches) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Create thread (This capa rule had 6 matches) [[1]](#1)| -|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Create thread (This capa rule had 1 match) [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Create thread (This capa rule had 1 match) [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Create thread (This capa rule had 2 matches) [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Dark Comet creates a thread. [[1]](#1)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR creates a thread. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon creates a thread. [[1]](#1)| +|[**Locky Bart**](../xample-malware/locky-bart.md)|2017|--|Locky Bart creates a thread. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Rombertik creates a thread. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon creates a thread. [[1]](#1)| ## References diff --git a/micro-behaviors/process/resume-thread.md b/micro-behaviors/process/resume-thread.md index 56ccdd8..3ece938 100644 --- a/micro-behaviors/process/resume-thread.md +++ b/micro-behaviors/process/resume-thread.md @@ -33,8 +33,8 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|Resume thread (This capa rule had 1 match) [[1]](#1)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Resume thread (This capa rule had 2 matches) [[1]](#1)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|CryptoLocker resumes thread. [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Dark Comet resumes a thread. [[1]](#1)| ## References diff --git a/micro-behaviors/process/set-thread-local-storage-value.md b/micro-behaviors/process/set-thread-local-storage-value.md index f4a54fd..9aa28d9 100644 --- a/micro-behaviors/process/set-thread-local-storage-value.md +++ b/micro-behaviors/process/set-thread-local-storage-value.md @@ -35,12 +35,12 @@ Malware allocates thread local storage. |Name|Date|Method|Description| |---|---|---|---| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Set thread local storage value (This capa rule had 1 match) [[1]](#1)| -|[**Gamut**](../xample-malware/gamut.md)|2014|--|Set thread local storage value (This capa rule had 1 match) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Set thread local storage value (This capa rule had 1 match) [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Set thread local storage value (This capa rule had 3 matches) [[1]](#1)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Set thread local storage value (This capa rule had 1 match) [[1]](#1)| -|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Set thread local storage value (This capa rule had 1 match) [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Dark Comet sets thread local storage values. [[1]](#1)| +|[**Gamut**](../xample-malware/gamut.md)|2014|--|Gamut sets thread local storage values. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon sets thread local storage values. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter sets thread local storage values. [[1]](#1)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|--|Redhip sets thread local storage values. [[1]](#1)| +|[**Rombertik**](../xample-malware/rombertik.md)|2015|--|Rombertik sets thread local storage values. [[1]](#1)| ## References diff --git a/micro-behaviors/process/suspend-thread.md b/micro-behaviors/process/suspend-thread.md index 9bad241..51920a5 100644 --- a/micro-behaviors/process/suspend-thread.md +++ b/micro-behaviors/process/suspend-thread.md @@ -33,10 +33,10 @@ |Name|Date|Method|Description| |---|---|---|---| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Suspend thread (This capa rule had 1 match) [[1]](#1)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|Suspend thread (This capa rule had 2 matches) [[1]](#1)| -|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|Suspend thread (This capa rule had 6 matches) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Suspend thread (This capa rule had 1 match) [[1]](#1)| +|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Dark Comet suspends threads. [[1]](#1)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR suspends threads. [[1]](#1)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|GravityRAT suspends threads. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon suspends threads. [[1]](#1)| ## References diff --git a/micro-behaviors/process/terminate-process.md b/micro-behaviors/process/terminate-process.md index 09398bc..055975b 100644 --- a/micro-behaviors/process/terminate-process.md +++ b/micro-behaviors/process/terminate-process.md @@ -34,15 +34,15 @@ Malware terminates a process. |Name|Date|Method|Description| |---|---|---|---| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Terminate process via fastfail (This capa rule had 1 match) [[1]](#1)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|Terminate process (This capa rule had 1 match) [[1]](#1)| -|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|Terminate process (This capa rule had 1 match) [[1]](#1)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Terminate process (This capa rule had 3 matches) [[1]](#1)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|Terminate process (This capa rule had 6 matches) [[1]](#1)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Terminate process (This capa rule had 1 match) [[1]](#1)| -|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Terminate process (This capa rule had 1 match) [[1]](#1)| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|Terminate process (This capa rule had 1 match) [[1]](#1)| -|[**UP007 Malware Family**](../xample-malware/up007.md)|2016|--|Terminate process (This capa rule had 2 matches) [[1]](#1)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy terminates a process via fastfail. [[1]](#1)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR terminates processes. [[1]](#1)| +|[**GravityRAT**](../xample-malware/gravity-rat.md)|2018|--|GravityRAT terminates processes. [[1]](#1)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon terminates processes. [[1]](#1)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|Kovter terminates processes. [[1]](#1)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon terminates processes. [[1]](#1)| +|[**Stuxnet**](../xample-malware/stuxnet.md)|2010|--|Stuxnet terminates processes. [[1]](#1)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|TrickBot terminates processes. [[1]](#1)| +|[**UP007**](../xample-malware/up007.md)|2016|--|UP007 terminates processes. [[1]](#1)| ## References diff --git a/persistence/component-firmware.md b/persistence/component-firmware.md index e7bf9c6..bd0b1d7 100644 --- a/persistence/component-firmware.md +++ b/persistence/component-firmware.md @@ -32,7 +32,7 @@ # Component Firmware -Malware may overwrite the flash memory of firmware outside of the main system firmware or BIOS. [[1]](#1). Methods related to malware (extending ATT&CK's definitions) are below. +Malware may overwrite the flash memory of firmware outside of the main system firmware or BIOS [[1]](#1). Methods related to malware (extending ATT&CK's definitions) are below. See ATT&CK: **Pre-OS Boot: Component Firmware ([T1542.002](https://attack.mitre.org/techniques/T1542/002/))**. @@ -48,9 +48,14 @@ See ATT&CK: **Pre-OS Boot: Component Firmware ([T1542.002](https://attack.mitre. |---|---|---|---| |[**SYNful Knock**](../xample-malware/synful-knock.md)|2015|F0009.001|SYNful Knock is a stealthy modification of the router's firmware image that can be used to maintain persistence within a victim's network. [[2]](#2)| + ## References [1] https://www.scmagazine.com/home/opinions/are-synful-knock-style-router-attacks-set-to-become-the-new-normal/ [2] https://www.fireeye.com/blog/threat-research/2015/09/synful_knock_-_acis.html +[3] http://researchcenter.paloaltonetworks.com/2015/10/yispecter-first-ios-malware-attacks-non-jailbroken-ios-devices-by-abusing-private-apis/ + +[4] https://www.mandiant.com/resources/synful-knock-acis + diff --git a/persistence/malicious-network-driver.md b/persistence/malicious-network-driver.md index efaf2b7..8050b47 100644 --- a/persistence/malicious-network-driver.md +++ b/persistence/malicious-network-driver.md @@ -36,7 +36,8 @@ A malicious network driver can tunnel outside traffic into the network, allowing |Name|Date|Method|Description| |---|---|---|---| -|**Malicious NDISProxy drivers**|June 2018|--|The LuckyMouse APT (aka APT27) spreads Trojans via malicious NDISProxy drivers. [[1]](#1)| +|[**Malicious NDISProxy drivers**]|2018|--|The LuckyMouse APT (aka APT27) spreads Trojans via malicious NDISProxy drivers. [[1]](#1)| + ## References diff --git a/persistence/modify-existing-service.md b/persistence/modify-existing-service.md index 2151606..df908fb 100644 --- a/persistence/modify-existing-service.md +++ b/persistence/modify-existing-service.md @@ -36,10 +36,12 @@ See ATT&CK: **Create or Modify System Process::Windows Service ([T1543.003](http |Name|Date|Method|Description| |---|---|---|---| -|[**YiSpecter**](../xample-malware/yispecter.md)|2015|--|Hijacks other installed applications' launch routines to use "ADPage" (an installed malicious app) to display advertisements [[2]](#2)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Locates an inactive driver service to Hijack and set it to start automatically [[3]](#3)| -|[**Conficker**](../xample-malware/conficker.md)|2008|--|Copies itself into the $systemroot%\system32 directory and registers as a service [[4]](#4)| -|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon enables the RemoteRegistry service to allow remote registry modification [[5]](#5)| +|[**YiSpecter**](../xample-malware/yispecter.md)|2015|--|The malware hijacks other installed applications' launch routines to use "ADPage" (an installed malicious app) to display advertisements. [[2]](#2)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|Malware locates an inactive driver service to hijack and set it to start automatically. [[3]](#3)| +|[**Conficker**](../xample-malware/conficker.md)|2008|--|Malware copies itself into the $systemroot%\system32 directory and registers as a service. [[4]](#4)| +|[**Shamoon**](../xample-malware/shamoon.md)|2012|--|Shamoon enables the RemoteRegistry service to allow remote registry modification. [[5]](#5)| +|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Vobfus disables Windows AutoUpdate and patches the first byte of TerminateProcess and TerminateThread API with C3 (RET Instruction) to prevent external processes from terminating the running instance of malware. [[6]](#6)| + ## References @@ -53,3 +55,4 @@ See ATT&CK: **Create or Modify System Process::Windows Service ([T1543.003](http [5] https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-returns-to-wipe-systems-in-middle-east-europe/ +[6] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ \ No newline at end of file diff --git a/persistence/registry-run-keys-startup-folder.md b/persistence/registry-run-keys-startup-folder.md index 655c02d..4bf56a3 100644 --- a/persistence/registry-run-keys-startup-folder.md +++ b/persistence/registry-run-keys-startup-folder.md @@ -36,21 +36,24 @@ See ATT&CK: **Boot or Logon Autostart Execution: Registry Run Keys / Startup Fol |Name|Date|Method|Description| |---|---|---|---| -|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|Trojan spyware program that has mainly been used for targeting banking sites. [[15]](#15)| -|[**Poison-Ivy**](../xample-malware/poison-ivy.md)|2005|--|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[2]](#2)| -|[**Hupigon**](../xample-malware/hupigon.md)|2013|F0012, E1547.001|Please see the Hupigon malware page for details. [[3]](#3)| -|[**Terminator**](../xample-malware/terminator.md)|May 2013|--|The Terminator rat sets "2019" as Windows' startup folder by modifying a registry value. [[4]](#4)| -|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|The malware creates an "autorun" registry key [[5]](#5)| -|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--| GoBotKR installs itself under registry run keys to establish persistence. [[6]](#6)| -|[**Kovter**](../xample-malware/kovter.md)|2016|--|The malware writes an autorun registry entry [[7]](#7)| +|[**TrickBot**](../xample-malware/trickbot.md)|2016|--|The malware has an auto-start service that allows it to run whenever the machine boots. [[16]](#16)| +|[**Poison Ivy**](../xample-malware/poison-ivy.md)|2005|--|To start itself at system boot, Poison Ivy adds registry entries. [[2]](#2)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|--|Hupigon drops the file "Systen.dll" and adds the registry entry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS DllName = "%System%\Systen.dll". [[3]](#3)| +|[**Hupigon**](../xample-malware/hupigon.md)|2013|E1547.001|Hupigon persists via Run registry key. [[3]](#3)| +|[**Terminator**](../xample-malware/terminator.md)|2013|--|The Terminator RAT sets "2019" as Windows' startup folder by modifying a registry value. [[4]](#4)| +|[**CryptoLocker**](../xample-malware/cryptolocker.md)|2013|--|The malware creates an "autorun" registry key. [[5]](#5)| +|[**GoBotKR**](../xample-malware/gobotkr.md)|2019|--|GoBotKR installs itself under registry run keys to establish persistence. [[6]](#6)| +|[**Kovter**](../xample-malware/kovter.md)|2016|--|The malware writes an autorun registry entry. [[7]](#7)| |[**Rombertik**](../xample-malware/rombertik.md)|2015|--|The malware will proceed to install itself in order to ensure persistence across system reboots before continuing on to execute the payload. To install itself, Rombertik first creates a VBS script named “fgf.vbs”, which is used to kick off Rombertik every time the user logs in, and places the script into the user’s Startup folder. [[8]](#8)| -|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|Adds registry entries to ensure automatic execution at every system startup [[9]](#9)| -|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder [[10]](#10)| -|[**Conficker**](../xample-malware/conficker.md)|2008|--|To start itself at system boot, the virus saces a copy of its DLL form to a random filename in the Windows system folder, then adds registry keys to have svchost.exe invoke that DLL as an invisible network service [[11]](#11)| -|[**Emotet**](../xample-malware/emotet.md)|2018|--|To start itself at system boot, Emotet adds the downloaded payload to the registry to maintain persistence [[13]](#13)| -|[**Bagle**](../xample-malware/bagle.md)|2004|--|Adds registry keys to enable its automatic execution at every system startup [[14]](#14)| -|[**Dark Comet**](../xample-malware/dark-comet.md)|2008|--|Adds several registry entries to enable automatic execution at startup [[12]](#12)| -|[**Redhip**](../xample-malware/rebhip.md)|2011|E1547.001|Persist via Run registry key (This capa rule had 4 matches) [[16]](#16)| +|[**Ursnif**](../xample-malware/ursnif.md)|2016|--|The malware adds registry entries to ensure automatic execution at system startup. [[9]](#9)| +|[**BlackEnergy**](../xample-malware/blackenergy.md)|2007|--|BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder, allowing it to persist via a Run registry key. [[10]](#10) [[17]](#17)| +|[**Conficker**](../xample-malware/conficker.md)|2008|--|To start itself at system boot, the virus saves a copy of its DLL form to a random filename in the Windows system folder, then adds registry keys to have svchost.exe invoke that DLL as an invisible network service. [[11]](#11)| +|[**DarkComet**](../xample-malware/darkcomet.md)|2008|--|DarkComet adds several registry entries to enable automatic execution at startup. [[12]](#12)| +|[**Emotet**](../xample-malware/emotet.md)|2018|--|To start itself at system boot, Emotet adds the downloaded payload to the registry to maintain persistence. [[13]](#13)| +|[**Bagle**](../xample-malware/bagle.md)|2004|--|Bagle adds registry keys to enable its automatic execution at every system startup. [[14]](#14)| +|[**Vobfus**](../xample-malware/vobfus.md)|2016|--|Malware adds registry keys to enable startup after reboot. [[15]](#15)| +|[**Redhip**](../xample-malware/rebhip.md)|2011|E1547.001|Redhip persists via a Run registry key. [[17]](#17)| + ## References @@ -82,13 +85,8 @@ See ATT&CK: **Boot or Logon Autostart Execution: Registry Run Keys / Startup Fol [14] https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/WORM_BAGLE.U/ -[15] https://www.trendmicro.com/en_us/research/18/k/trickbot-shows-off-new-trick-password-grabber-module.html +[15] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ -[16] capa v4.0, analyzed at MITRE on 10/12/2022 - -[17] https://labs.vipre.com/analysis-of-kovter-a-very-clever-piece-of-malware/#:~:text=Kovter%20copies%20the%20fileless%20persistence,written%20on%20to%20the%20filesystem. - -[18] https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/poisonivy - -[19] https://www.mandiant.com/resources/hot-knives-through-butter-evading-file-based-sandboxes +[16] https://www.trendmicro.com/en_us/research/18/k/trickbot-shows-off-new-trick-password-grabber-module.html +[17] capa v4.0, analyzed at MITRE on 10/12/2022 diff --git a/privilege-escalation/install-certificate.md b/privilege-escalation/install-certificate.md index 6d0b242..fe4193f 100644 --- a/privilege-escalation/install-certificate.md +++ b/privilege-escalation/install-certificate.md @@ -34,7 +34,7 @@ Malware may install a certificate to gain access to https traffic. |Name|Date|Method|Description| |---|---|---|---| -|[**SearchAwesome**](../xample-malware/searchawesome.md)|2015|--|The malware installs a certificate. [[1]](#1)| +|[**SearchAwesome**](../xample-malware/searchawesome.md)|2018|--|The malware installs a certificate. [[1]](#1)| ## References diff --git a/xample-malware/README.md b/xample-malware/README.md index 094a9d6..753630e 100644 --- a/xample-malware/README.md +++ b/xample-malware/README.md @@ -12,39 +12,42 @@ Please see [Poison-Ivy X0014](../xample-malware/poison-ivy.md) and [Kovter X0009 * **Bagle** [X0001](../xample-malware/bagle.md) * **Black Energy** [X0002](../xample-malware/blackenergy.md) -* **Chopstick** [X0035](../xample-malware/chopstick.md) -* **Clipminer** [X0038](../xample-malware/clipminer.md) -* **Conficker** [X0003](../xample-malware/conficker.md) -* **CozyCar** [X0034](../xample-malware/cozycar.md) -* **CryptoLocker** [X0030](../xample-malware/cryptolocker.md) -* **CryptoWall** [X0029](../xample-malware/cryptowall.md) -* **Dark Comet** [X0004](../xample-malware/dark-comet.md) -* **DNSChanger** [X0005](../xample-malware/dnschanger.md) -* **Emotet** [X0028](../xample-malware/emotet.md) -* **EvilBunny** [X0036](../xample-malware/evilbunny.md) -* **Gamut** [X0006](../xample-malware/gamut.md) -* **Geneio** [X0007](../xample-malware/geneio.md) -* **GoBotKR** [X0027](../xample-malware/gobotkr.md) -* **GravityRAT** [X0032](../xample-malware/gravity-rat.md) -* **Heriplor** [X0026](../xample-malware/heriplor.md) -* **Hupigon** [X0008](../xample-malware/hupigon.md) -* **Kovter** [X0009](../xample-malware/kovter.md) -* **Kraken** [X0010](../xample-malware/kraken.md) -* **Locky Bart** [X0011](../xample-malware/locky-bart.md) -* **Mazarbot** [X0012](../xample-malware/mazarbot.md) -* **Mebromi** [X0013](../xample-malware/mebromi.md) -* **Netwalker** [X0037](../xample-malware/netwalker.md) -* **Poison-Ivy** [X0014](../xample-malware/poison-ivy.md) -* **Redhip** [X0015](../xample-malware/rebhip.md) -* **Rombertik** [X0031](../xample-malware/rombertik.md) -* **SamSam** [X0016](../xample-malware/samsam.md) -* **SearchAwesome** [X0017](../xample-malware/searchawesome.md) -* **Shamoon** [X0018](../xample-malware/shamoon.md) -* **Stuxnet** [X0019](../xample-malware/stuxnet.md) -* **SYNful Knock** [X0020](../xample-malware/synful-knock.md) -* **Terminator** [X0021](../xample-malware/terminator.md) -* **TrickBot** [X0025](../xample-malware/trickbot.md) -* **UP007** [X0033](../xample-malware/up007.md) -* **Ursnif** [X0022](../xample-malware/ursnif.md) -* **WebCobra** [X0023](../xample-malware/webcobra.md) -* **YiSpecter** [X0024](../xample-malware/yispecter.md) +* **Chopstick** [X0003](../xample-malware/chopstick.md) +* **Clipminer** [X0004](../xample-malware/clipminer.md) +* **Conficker** [X0005](../xample-malware/conficker.md) +* **CozyCar** [X0006](../xample-malware/cozycar.md) +* **CryptoLocker** [X0007](../xample-malware/cryptolocker.md) +* **CryptoWall** [X0008](../xample-malware/cryptowall.md) +* **Dark Comet** [X0009](../xample-malware/dark-comet.md) +* **DNSChanger** [X0010](../xample-malware/dnschanger.md) +* **Emotet** [X0011](../xample-malware/emotet.md) +* **EvilBunny** [X0012](../xample-malware/evilbunny.md) +* **Gamut** [X0013](../xample-malware/gamut.md) +* **Geneio** [X0014](../xample-malware/geneio.md) +* **GoBotKR** [X0015](../xample-malware/gobotkr.md) +* **GravityRAT** [X0016](../xample-malware/gravity-rat.md) +* **Heriplor** [X0017](../xample-malware/heriplor.md) +* **Hupigon** [X0018](../xample-malware/hupigon.md) +* **Kovter** [X0019](../xample-malware/kovter.md) +* **Kraken** [X0020](../xample-malware/kraken.md) +* **Locky Bart** [X0021](../xample-malware/locky-bart.md) +* **Matanbuchus** [X0022](../xample-malware/matanbuchus.md) +* **Mazarbot** [X0023](../xample-malware/mazarbot.md) +* **Mebromi** [X0024](../xample-malware/mebromi.md) +* **Netwalker** [X0025](../xample-malware/netwalker.md) +* **Poison-Ivy** [X0026](../xample-malware/poison-ivy.md) +* **Redhip** [X0027](../xample-malware/rebhip.md) +* **Rombertik** [X0028](../xample-malware/rombertik.md) +* **SamSam** [X0029](../xample-malware/samsam.md) +* **SearchAwesome** [X0030](../xample-malware/searchawesome.md) +* **Shamoon** [X0031](../xample-malware/shamoon.md) +* **Stuxnet** [X0032](../xample-malware/stuxnet.md) +* **SYNful Knock** [X0033](../xample-malware/synful-knock.md) +* **Teardrop** [X0034](../xample-malware/teardrop.md) +* **Terminator** [X0035](../xample-malware/terminator.md) +* **TrickBot** [X0036](../xample-malware/trickbot.md) +* **UP007** [X0037](../xample-malware/up007.md) +* **Ursnif** [X0038](../xample-malware/ursnif.md) +* **Vobfus** [X0039](../xample-malware/vobfus.md) +* **WebCobra** [X0040](../xample-malware/webcobra.md) +* **YiSpecter** [X0041](../xample-malware/yispecter.md) diff --git a/xample-malware/bagle.md b/xample-malware/bagle.md index 23cb57d..52cb6d1 100644 --- a/xample-malware/bagle.md +++ b/xample-malware/bagle.md @@ -30,15 +30,17 @@ A mass-mailing computer worm affecting Microsoft Windows. [[1]](#1) |Name|Use| |---|---| -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|Adds registry keys to enable its automatic execution at every system startup [[1]](#1) | +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|Malware adds registry keys to enable its automatic execution at every system startup. [[1]](#1)| + ## MBC Behaviors |Name|Use| |---|---| -|[Impact::Prevent Concurrent Execution (B0024)](../execution/prevent-concurrent-execution.md)|Some variants look for an unnamed mutex to ensure only one copy of itself is running on a system [[1]](#1) | -|[Execution::Send Email (B0020)](../execution/send-email.md)|Bagle uses its own SMTP engine to mass-mail itself as an attachment from an infected computer [[2]](#2) | -|[Data::Decompress Data::aPLib (C0025.003)](../micro-behaviors/data/decompress-data.md)|Decompress data using aPLib (This capa rule had 1 match) [[4]](#4) | +|[Execution::Prevent Concurrent Execution (B0024)](../execution/prevent-concurrent-execution.md)|Some Bagle variants look for an unnamed mutex to ensure only one copy of itself is running on a system. [[1]](#1)| +|[Execution::Send Email (B0020)](../execution/send-email.md)|Bagle uses its own SMTP engine to mass-mail itself as an attachment from an infected computer. [[2]](#2)| +|[Micro-Behaviors::Data::Decompress Data::aPLib (C0025.003)](../micro-behaviors/data/decompress-data.md)|Bagle decompresses data using aPLib. [[4]](#4)| + ## Indicators of Compromise @@ -55,4 +57,3 @@ SHA256 Hashes [3] https://www.joesandbox.com/analysis/561298/0/html [4] capa v4.0, analyzed at MITRE on 10/12/2022 - diff --git a/xample-malware/blackenergy.md b/xample-malware/blackenergy.md index 7594d5a..5216e80 100644 --- a/xample-malware/blackenergy.md +++ b/xample-malware/blackenergy.md @@ -30,7 +30,7 @@ An HTTP-based botnet used mostly for DDoS attacks. [[1]](#1) |Name|Use| |---|---| -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Access PEB ldr_data (This capa rule had 1 match) [[4]](#4)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|BlackEnergy accesses PEB ldr_data. [[4]](#4)| See ATT&CK: [BlackEnergy - Techniques Used](https://attack.mitre.org/software/S0089/). @@ -38,40 +38,42 @@ See ATT&CK: [BlackEnergy - Techniques Used](https://attack.mitre.org/software/S0 |Name|Use| |---|---| -|[Defense Evasion::Process Injection::Injection using Shims (E1055.m05)](../defense-evasion/process-injection.md)|Bypasses UAC using a Shim Database instructing SndVol.exe to execute cmd.exe instead, allowing for elevated execution [[1]](#1) | -|[Defense Evasion::Install Insecure or Malicious Configuration (B0047)](../defense-evasion/install-insecure-or-malicious-configuration.md)|Configures the system to the TESTSIGNING boot configuration option to load its unsigned driver component [[1]](#1) | -|[Defense Evasion::Indicator Blocking (F0006)](../defense-evasion/indicator-blocking.md)|Clears windows event logs and removes the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevent strings in the user32.dll.mui of the system [[1]](#1) | -|[Persistence::Modify Existing Service (F0011)](../persistence/modify-existing-service.md)|Locates an inactive driver service to Hijack and set it to start automatically [[1]](#1) | -|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|Injects its dll component into svchost.exe [[1]](#1) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Uses Systeminfo to gather OS version, system configuration, BIOS, the motherboard, and processor [ [[1]](#1) | -|[Collection::Keylogging (F0002)](../collection/keylogging.md)|Keylogger plugin allows for collection of keystrokes [[2]](#2) | -|[Collection::Screen Capture (E1113)](../collection/screen-capture.md)|Screenshot plugin allows for collection of screenshots [[2]](#2) | -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder [[1]](#1) Persist via Run registry key (This capa rule had 1 match) [[4]](#4)| -|[Impact::Data Destruction (E1485)](../impact/data-destruction.md)|BlackEnergy 2 variant contains a Destroy plugin that destroys data stored on victim hard drives by overwriting file contents [[3]](#3) | -|[Defense Evasion::Obfuscated Files or Information::Encryption-Standard Algorithm (E1027.m05)](../defense-evasion/obfuscated-files-or-information.md)|Encrypt data using RC4 via WinAPI (This capa rule had 1 match) [[4]](#4) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Get common file path (This capa rule had 3 matches) [[4]](#4) | +|[Defense Evasion::Process Injection::Injection using Shims (E1055.m05)](../defense-evasion/process-injection.md)|Malware bypasses UAC using a Shim Database instructing SndVol.exe to execute cmd.exe instead, allowing for elevated execution. [[1]](#1)| +|[Defense Evasion::Install Insecure or Malicious Configuration (E1479)](../defense-evasion/install-insecure-or-malicious-configuration.md)|Malware configures the system to the TESTSIGNING boot configuration option to load its unsigned driver component. [[1]](#1)| +|[Defense Evasion::Indicator Blocking (F0006)](../defense-evasion/indicator-blocking.md)|Malware clears windows event logs and removes the watermark associated with enabling the TESTSIGNING boot configuration option by removing the relevent strings in the user32.dll.mui of the system. [[1]](#1)| +|[Persistence::Modify Existing Service (F0011)](../persistence/modify-existing-service.md)|Malware locates an inactive driver service to Hijack and set it to start automatically. [[1]](#1)| +|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|Malware injects its dll component into svchost.exe. [[1]](#1)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Malware uses Systeminfo to gather OS version, system configuration, BIOS, the motherboard, and processor. [[1]](#1)| +|[Collection::Keylogging (F0002)](../collection/keylogging.md)|Keylogger plugin allows for collection of keystrokes. [[2]](#2)| +|[Collection::Screen Capture (E1113)](../collection/screen-capture.md)|Malware contains a screenshot plugin that allows for the collection of screenshots. [[2]](#2)| +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|BlackEnergy 3 variant drops its main DLL component and then creates a .lnk shortcut to that file in the startup folder, allowing it to persist via a Run registry key. [[1]](#1) [[4]](#4)| +|[Impact::Data Destruction (E1485)](../impact/data-destruction.md)|BlackEnergy 2 variant contains a Destroy plugin that destroys data stored on victim hard drives by overwriting file contents. [[3]](#3)| +|[Defense Evasion::Obfuscated Files or Information::Encryption-Standard Algorithm (E1027.m05)](../defense-evasion/obfuscated-files-or-information.md)|BlackEnergy encrypts data using RC4 via WinAPI. [[4]](#4)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|BlackEnergy gets the common file path. [[4]](#4)| + ## MBC Behaviors |Name|Use| |---|---| -|[Impact::Denial of Service (B0033)](../impact/denial-of-service.md)|Originally built to launch distributed denial of service attacks that can target more than one IP address per hostname [[1]](#1) | -|[Execution::Remote Commands (B0011)](../execution/remote-commands.md)|Infected bots receive commands from botmaster to load plugins associated with botmaster's goals [[1]](#1) | -|[Anti-Static Analysis::Disassembler Evasion::Argument Obfuscation (B0012.001)](../anti-static-analysis/disassembler-evasion.md)|Contain obfuscated stackstrings (This capa rule had 3 matches) [[4]](#4) | -|[Communication::HTTP Communication::Extract Body (C0002.011)](../micro-behaviors/communication/http-communication.md)|Extract HTTP body (This capa rule had 1 match) [[4]](#4) | -|[Communication::HTTP Communication::IWebBrowser (C0002.010)](../micro-behaviors/communication/http-communication.md)|Initialize IWebBrowser2 (This capa rule had 1 match) [[4]](#4) | -|[Cryptography::Cryptographic Hash (C0029)](../micro-behaviors/cryptography/cryptographic-hash.md)|Hash data via WinCrypt (This capa rule had 2 matches) [[4]](#4) | -|[Cryptography::Cryptographic Hash::MD5 (C0029.001)](../micro-behaviors/cryptography/cryptographic-hash.md)|Hash data with MD5 (This capa rule had 1 match) [[4]](#4) | -|[Cryptography::Cryptographic Hash::SHA1 (C0029.002)](../micro-behaviors/cryptography/cryptographic-hash.md)|Hash data using SHA1 (This capa rule had 1 match) [[4]](#4) | -|[Cryptography::Decrypt Data (C0031)](../micro-behaviors/cryptography/decrypt-data.md)|Encrypt or decrypt via WinCrypt (This capa rule had 1 match) [[4]](#4) | -|[Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Encrypt data using RC4 via WinAPI (This capa rule had 1 match) [[4]](#4) | -|[Cryptography::Encryption Key (C0028)](../micro-behaviors/cryptography/encryption-key.md)|Create new key via CryptAcquireContext (This capa rule had 1 match) [[4]](#4) | -|[Cryptography::Generate Pseudo-random Sequence::Use API (C0021.003)](../micro-behaviors/cryptography/generate-pseudorandom-sequence.md)|Generate random numbers via WinAPI (This capa rule had 1 match) [[4]](#4) | -|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Enumerate PE sections (This capa rule had 1 match) [[4]](#4) | -|[Operating System::Registry::Query Registry Key (C0036.005)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry key (This capa rule had 1 match) [[4]](#4) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 7 matches) [[4]](#4) | -|[Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Create process on Windows (This capa rule had 2 matches) [[4]](#4) | -|[Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Terminate process via fastfail (This capa rule had 1 match) [[4]](#4) | +|[Impact::Denial of Service (B0033)](../impact/denial-of-service.md)|Malware was originally built to launch a distributed denial of service attacks that can target more than one IP address per hostname. [[1]](#1)| +|[Execution::Remote Commands (B0011)](../execution/remote-commands.md)|Malware-infected bots receive commands from botmaster to load plugins associated with botmaster's goals. [[1]](#1)| +|[Anti-Static Analysis::Disassembler Evasion::Argument Obfuscation (B0012.001)](../anti-static-analysis/disassembler-evasion.md)|BlackEnergy contains obfuscated stack strings. [[4]](#4) | +|[Micro-Behaviors::Communication::HTTP Communication::Extract Body (C0002.011)](../micro-behaviors/communication/http-communication.md)|BlackEnergy extracts the HTTP body. [[4]](#4)| +|[Micro-Behaviors::Communication::HTTP Communication::IWebBrowser (C0002.010)](../micro-behaviors/communication/http-communication.md)|The malware initializes IWebBrowser2. [[4]](#4)| +|[Micro-Behaviors::Cryptography::Cryptographic Hash (C0029)](../micro-behaviors/cryptography/cryptographic-hash.md)|BlackEnergy hashes data via WinCrypt. [[4]](#4)| +|[Micro-Behaviors::Cryptography::Cryptographic Hash::MD5 (C0029.001)](../micro-behaviors/cryptography/cryptographic-hash.md)|BlackEnergy hashes data with MD5. [[4]](#4)| +|[Micro-Behaviors::Cryptography::Cryptographic Hash::SHA1 (C0029.002)](../micro-behaviors/cryptography/cryptographic-hash.md)|BlackEnergy hashes data using SHA1. [[4]](#4)| +|[Micro-Behaviors::Cryptography::Decrypt Data (C0031)](../micro-behaviors/cryptography/decrypt-data.md)|BlackEnergy encrypts or decrypts via WinCrypt. [[4]](#4)| +|[Micro-Behaviors::Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|BlackEnergy encrypts data using RC4 via WinAPI. [[4]](#4)| +|[Micro-Behaviors::Cryptography::Encryption Key (C0028)](../micro-behaviors/cryptography/encryption-key.md)|BlackEnergy creates new key via CryptAcquireContext. [[4]](#4)| +|[Micro-Behaviors::Cryptography::Generate Pseudo-random Sequence::Use API (C0021.003)](../micro-behaviors/cryptography/generate-pseudorandom-sequence.md)|BlackEnergy generates random numbers via WinAPI. [[4]](#4)| +|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|BlackEnergy enumerates PE sections. [[4]](#4)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Key (C0036.005)](../micro-behaviors/operating-system/registry.md)|BlackEnergy queries or enumerates a registry key. [[4]](#4)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|BlackEnergy queries or enumerates a registry value. [[4]](#4)| +|[Micro-Behaviors::Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|BlackEnergy creates a process on Windows. [[4]](#4)| +|[Micro-Behaviors::Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|BlackEnergy terminates a process via fastfail. [[4]](#4)| + ## Indicators of Compromise diff --git a/xample-malware/chopstick.md b/xample-malware/chopstick.md index 3ff6dac..07e4599 100644 --- a/xample-malware/chopstick.md +++ b/xample-malware/chopstick.md @@ -2,7 +2,7 @@ - + @@ -35,19 +35,19 @@ See ATT&CK: [CHOPSTICK - Techniques Used](https://attack.mitre.org/software/S002 |Name|Use| |---|---| -|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|CHOPSTICK may encrypt and store configuration data inside a registry key [[1]](#1)| -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|CHOPSTICK collects information from the host including Windows version, CPU architecture, and UAC settings [[1]](#1)| -|[Defense Evasion::Hidden Files and Directories (F0005)](../defense-evasion/hidden-files-and-directories.md)|CHOPSTICK creates a hidden file for temporary storage [[1]](#1)| -|[Collection::Keylogging (F0002)](../collection/keylogging.md)|CHOPSTICK collects user keystrokes [[1]](#1)| -|[Collection::Screen Capture (E1113)](../collection/screen-capture.md)|CHOPSTICK takes snapshots of deskop and window contents [[1]](#1)| -|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|CHOPSTICK sends data to the C2 server using HTTP POST requests [[1]](#1)| +|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|CHOPSTICK may encrypt and store configuration data inside a registry key. [[1]](#1)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|CHOPSTICK collects information from the host including Windows version, CPU architecture, and UAC settings. [[1]](#1)| +|[Defense Evasion::Hidden Files and Directories (F0005)](../defense-evasion/hidden-files-and-directories.md)|CHOPSTICK creates a hidden file for temporary storage. [[1]](#1)| +|[Collection::Keylogging (F0002)](../collection/keylogging.md)|CHOPSTICK collects user keystrokes. [[1]](#1)| +|[Collection::Screen Capture (E1113)](../collection/screen-capture.md)|CHOPSTICK takes snapshots of deskop and window contents. [[1]](#1)| +|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|CHOPSTICK sends data to the C2 server using HTTP POST requests. [[1]](#1)| ## MBC Behaviors |Name|Use| |---|---| -|[Micro-Objective::Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|CHOPSTICK encrypts the configuration block using RC4 encryption [[1]](#1)| +|[Micro-Objective::Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|CHOPSTICK encrypts the configuration block using RC4 encryption. [[1]](#1)| ## Indicators of Compromise diff --git a/xample-malware/clipminer.md b/xample-malware/clipminer.md index 475b3c0..c32e3dd 100644 --- a/xample-malware/clipminer.md +++ b/xample-malware/clipminer.md @@ -2,7 +2,7 @@
IDX0035X0003
Aliases
- + @@ -25,32 +25,32 @@ # Clipminer -Malware used for cryptocurrency mining and clipboard hijacking +Malware used for cryptocurrency mining and clipboard hijacking. ## ATT&CK Techniques |Name|Use| |---|---| -|[Defense Evasion::Masquerading (T1036)](https://attack.mitre.org/techniques/T1036/)|Clipminer drops a file masquerading as a Control Panel (CPL) file [[1]](#1)| -|[Persistence::Scheduled Task/Job (T1053)](https://attack.mitre.org/techniques/T1053/)|Clipminer creates scheduled tasks for persistence [[1]](#1)| +|[Defense Evasion::Masquerading (T1036)](https://attack.mitre.org/techniques/T1036/)|Clipminer drops a file masquerading as a Control Panel (CPL) file. [[1]](#1)| +|[Persistence::Scheduled Task/Job (T1053)](https://attack.mitre.org/techniques/T1053/)|Clipminer creates scheduled tasks for persistence. [[1]](#1)| ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|Clipminer edits the registry [[1]](#1)| -|[Command and Control::C2 Communication (B0030)](../command-and-control/c2-communication.md)|Clipminer communicates to a Tor Onion Service via HTTP [[1]](#1)| -|[Collection::Input Capture (E1056)](../collection/input-capture.md)|Clipminer monitors keyboard and mouse activity to determine if the machine is in use [[1]](#1)| -|[Impact::Clipboard Modification (E1510)](../impact/clipboard-modification.md)|Clipminer monitors the clipboard for cryptocurrency addresses and replaces them with ones controlled by the adversary [[1]](#1)| +|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|Clipminer edits the registry. [[1]](#1)| +|[Command and Control::C2 Communication (B0030)](../command-and-control/c2-communication.md)|Clipminer communicates to a Tor Onion Service via HTTP. [[1]](#1)| +|[Collection::Input Capture (E1056)](../collection/input-capture.md)|Clipminer monitors keyboard and mouse activity to determine if the machine is in use. [[1]](#1)| +|[Impact::Clipboard Modification (E1510)](../impact/clipboard-modification.md)|Clipminer monitors the clipboard for cryptocurrency addresses and replaces them with ones controlled by the adversary. [[1]](#1)| ## MBC Behaviors |Name|Use| |---|---| -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)| Upon execution, ClipMiner drops a Control Panel file [[1]](#1)| -|[Impact::Resource Hijacking (B0018)](../impact/resource-hijacking.md)|Clipminer uses sytem resources to mine for cryptocurrency [[1]](#1)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)| Upon execution, Clipminer drops a file masquerading as a Control Panel (CPL) file. [[1]](#1)| +|[Impact::Resource Hijacking (B0018)](../impact/resource-hijacking.md)|Clipminer uses sytem resources to mine for cryptocurrency. [[1]](#1)| ## Indicators of Compromise diff --git a/xample-malware/conficker.md b/xample-malware/conficker.md index def881a..b8f7605 100644 --- a/xample-malware/conficker.md +++ b/xample-malware/conficker.md @@ -2,7 +2,7 @@
IDX0038X0004
Aliases
- + @@ -31,20 +31,21 @@ A worm targeting Microsoft Windows operations systems. |Name|Use| |---|---| -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|To start itself at system boot, the virus saces a copy of its DLL form to a random filename in the Windows system folder, then adds registry keys to have svchost.exe invoke that DLL as an invisible network service [[1]](#1)| -|[Persistence::Modify Existing Service (F0011)](../persistence/modify-existing-service.md)|Copies itself into the $systemroot%\system32 directory and registers as a service [[1]](#1)| -|[Defense Evasion::Indicator Blocking (F0006)](../defense-evasion/indicator-blocking.md)|Terminates various services related to system security and Windows and prevents network access to various websites related to antivirus software [[1]](#1)| -|[Impact::Data Destruction (E1485)](../impact/data-destruction.md)|resets system restore points and deletes backup files [[1]](#1)| -|[Anti-Static Analysis::Software Packing::UPX (F0001.008)](../anti-static-analysis/software-packing.md)|Conficker is propagated as a DLL which has been backed using the UPX packer [[2]](#2) | +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|To start itself at system boot, the virus saves a copy of its DLL form to a random filename in the Windows system folder, then adds registry keys to have svchost.exe invoke that DLL as an invisible network service. [[1]](#1)| +|[Persistence::Modify Existing Service (F0011)](../persistence/modify-existing-service.md)|The malware copies itself into the $systemroot%\system32 directory and registers as a service. [[1]](#1)| +|[Defense Evasion::Indicator Blocking (F0006)](../defense-evasion/indicator-blocking.md)|The malware terminates various services related to system security and Windows and prevents network access to various websites related to antivirus software. [[1]](#1)| +|[Impact::Data Destruction (E1485)](../impact/data-destruction.md)|The malware resets system restore points and deletes backup files. [[1]](#1)| +|[Anti-Static Analysis::Software Packing::UPX (F0001.008)](../anti-static-analysis/software-packing.md)|Conficker is propagated as a DLL which has been backed using the UPX packer. [[2]](#2)| + ## MBC Behaviors |Name|Use| |---|---| -|[Command and Control::Domain Name Generation (B0031)](../command-and-control/domain-name-generation.md)|Uses a domain name generator seeded by the current date to ensure that every copy of the virus generates the same names on their respective days [[1]](#1)| -|[Execution::Conditional Execution (B0025)](../execution/conditional-execution.md)|Conficker A has routine that causes the process to suicide exit if the keyboard language layout is set to Ukranian [[1]](#1)| -|[Micro-Behavior::Memory::Overflow Buffer (C0010)](../micro-behaviors/memory/overflow-buffer.md)|Variants A, B, C, and E exploit a vulnerability in the Server Service on Windows computers in which an already compromised computer sends a specially-crafted RPC request to force a buffer overflow and execute shellcode on the target computer [[1]](#1)| -|[Execution::Conditional Execution::Suicide Exit (B0025.001)](../execution/conditional-execution.md)|Conficker B has significantly more suicide logic embedded in its code and employs anti-debugging features to avoid reverse engineering attempts [[2]](#2)| +|[Command and Control::Domain Name Generation (B0031)](../command-and-control/domain-name-generation.md)|Conficker uses a domain name generator seeded by the current date to ensure that every copy of the virus generates the same names on their respective days. [[1]](#1)| +|[Execution::Conditional Execution (B0025)](../execution/conditional-execution.md)|Conficker A variant has a routine that causes the process to suicide exit if the keyboard language layout is set to Ukranian. [[1]](#1)| +|[Micro-Behaviors::Memory::Overflow Buffer (C0010)](../micro-behaviors/memory/overflow-buffer.md)|Variants A, B, C, and E exploit a vulnerability in the Server Service on Windows computers in which an already compromised computer sends a specially-crafted RPC request to force a buffer overflow and execute shellcode on the target computer. [[1]](#1)| +|[Execution::Conditional Execution::Suicide Exit (B0025.001)](../execution/conditional-execution.md)|Conficker B variant has significantly more suicide logic embedded in its code and employs anti-debugging features to avoid reverse engineering attempts. [[2]](#2)| ## Indicators of Compromise diff --git a/xample-malware/cozycar.md b/xample-malware/cozycar.md index 39bcddd..18ed180 100644 --- a/xample-malware/cozycar.md +++ b/xample-malware/cozycar.md @@ -2,7 +2,7 @@
IDX0003X0005
Aliases
- + @@ -35,16 +35,17 @@ See ATT&CK: [CozyCar - Techniques Used](https://attack.mitre.org/software/S0046/ |Name|Use| |---|---| -|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|CozyCar requests a file using SSL to a C2 domain [[1]](#1)| -|[Defense Evasion::Self Deletion (F0007)](../defense-evasion/self-deletion.md)|CozyCar has a dll file that serves as a cleanup mechanism for its dropped binary [[1]](#1)| -|[Command and Control::C2 Communication (B0030)](../command-and-control/c2-communication.md)|CozyCar communicates with a C2 server [[1]](#1)| +<<<<<<< HEAD +|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|CozyCar requests a file using SSL to a C2 domain. [[1]](#1)| +|[Defense Evasion::Self Deletion (F0007)](../defense-evasion/self-deletion.md)|CozyCar has a dll file that serves as a cleanup mechanism for its dropped binary. [[1]](#1)| +|[Command and Control::C2 Communication (B0030)](../command-and-control/c2-communication.md)|CozyCar communicates with a C2 server. [[1]](#1)| ## MBC Behaviors |Name|Use| |---|---| -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)| Upon execution, CozyCar drops a decoy file and a secondary dropper [[1]](#1)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)| Upon execution, CozyCar drops a decoy file and a secondary dropper. [[1]](#1)| ## Indicators of Compromise diff --git a/xample-malware/cryptolocker.md b/xample-malware/cryptolocker.md index 29c5e62..b272995 100644 --- a/xample-malware/cryptolocker.md +++ b/xample-malware/cryptolocker.md @@ -1,7 +1,7 @@
IDX0034X0006
Aliases
- + @@ -31,36 +31,39 @@ CryptoLocker is a family of ransomware. [[1]](#1) |Name|Use| |---|---| -|[Initial Access::Spearphishing Attachment (T1566.001)](https://attack.mitre.org/techniques/T1566/001/)|The malware is sent to victims as an attachment [[1]](#1) | -|[Command and Control::Encrypted Channel::Asymmetric Cryptography (T1573.002)](https://attack.mitre.org/techniques/T1573/002/)|The malware encrypts messages with a public RSA key [[1]](#1) | -|[Command and Control::Application Layer Protocol::Web Protocols (T1071.001)](https://attack.mitre.org/techniques/T1071/001/)|The malware uses http to communicate with C2 [[1]](#1) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Link many functions at runtime (This capa rule had 1 match) [[2]](#2) | +|[Initial Access::Spearphishing Attachment (T1566.001)](https://attack.mitre.org/techniques/T1566/001/)|The malware is sent to victims as an attachment. [[1]](#1)| +|[Command and Control::Encrypted Channel::Asymmetric Cryptography (T1573.002)](https://attack.mitre.org/techniques/T1573/002/)|The malware encrypts messages with a public RSA key. [[1]](#1)| +|[Command and Control::Application Layer Protocol::Web Protocols (T1071.001)](https://attack.mitre.org/techniques/T1071/001/)|The malware uses http to communicate with C2. [[1]](#1)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|The malware links many functions at runtime. [[2]](#2)| + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Impact::Data Encrypted for Impact::Ransom Note (E1486.001)](../impact/data-encrypted-for-impact.md)|The malware launches Internet Explorer to show ransom notes [[1]](#1) | -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|The malware creates an "autorun" registry key [[1]](#1) | -|[Execution::User Execution (E1204)](../execution/user-execution.md)|The malware relies on victims to execute [[1]](#1) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|The malware searches for user files before encrypting them [[1]](#1) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 1 match) [[2]](#2) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Query environment variable (This capa rule had 1 match) [[2]](#2) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Accept command line arguments (This capa rule had 2 matches) [[2]](#2) | +|[Impact::Data Encrypted for Impact::Ransom Note (E1486.001)](../impact/data-encrypted-for-impact.md)|The malware launches Internet Explorer to show ransom notes. [[1]](#1)| +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|The malware creates an "autorun" registry key. [[1]](#1)| +|[Execution::User Execution (E1204)](../execution/user-execution.md)|The malware relies on victims to execute. [[1]](#1)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|The malware searches for user files before encrypting them. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|CryptoLocker encodes data using XOR. [[2]](#2)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|CryptoLocker queries environment variables. [[2]](#2)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|CryptoLocker accepts command line arguments. [[2]](#2)| + ## MBC Behaviors |Name|Use| |---|---| -|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|The malware sends a hash value generated from system information [[1]](#1) | -|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|The malware receives a public key from the C2 [[1]](#1) | -|[Command and Control::Domain Name Generation (B0031)](../command-and-control/domain-name-generation.md)|The malware uses an internal domain generation algorithm [[1]](#1) | -|[Command and Control::C2 Communication::Authenticate (B0030.011)](../command-and-control/c2-communication.md)|The malware sends a phone-home message with encryption to start [[1]](#1) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 1 match) [[2]](#2) | -|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Enumerate PE sections (This capa rule had 1 match) [[2]](#2) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Writes Fileon Windows (This capa rule had 1 match) [[2]](#2) | -|[Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Allocate RWX memory (This capa rule had 1 match) [[2]](#2) | -|[Process::Resume Thread (C0054)](../micro-behaviors/process/resume-thread.md)|Resume thread (This capa rule had 1 match) [[2]](#2) | +|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|The malware sends a hash value generated from system information. [[1]](#1)| +|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|The malware receives a public key from the C2. [[1]](#1)| +|[Command and Control::Domain Name Generation (B0031)](../command-and-control/domain-name-generation.md)|The malware uses an internal domain generation algorithm. [[1]](#1)| +|[Command and Control::C2 Communication::Authenticate (B0030.011)](../command-and-control/c2-communication.md)|The malware sends a phone-home message with encryption to start. [[1]](#1)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|CryptoLocker encodes data using XOR. [[2]](#2)| +|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|CryptoLocker enumerates PE sections. [[2]](#2)| +|[Micro-Behaviors::File System::Writes File (C0052)](../micro-behaviors/file-system/writes-file.md)|CryptoLocker writes Fileon Windows. [[2]](#2)| +|[Micro-Behaviors::Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|CryptoLocker allocates RWX memory. [[2]](#2)| +|[Micro-Behaviors::Process::Resume Thread (C0054)](../micro-behaviors/process/resume-thread.md)|CryptoLocker resumes thread. [[2]](#2)| + ## Indicators of Compromise diff --git a/xample-malware/cryptowall.md b/xample-malware/cryptowall.md index f8e175e..ce38db5 100644 --- a/xample-malware/cryptowall.md +++ b/xample-malware/cryptowall.md @@ -2,7 +2,7 @@
IDX0030X0007
Aliases
- + @@ -32,24 +32,28 @@ CryptoWall is a family of ransomware. [[1]](#1) |Name|Use| |---|---| -|[Initial Access::Spearphishing Attachment (T1566.001)](https://attack.mitre.org/techniques/T1566/001/)| The malware file is sent as an attachment [[1]](#1)| -|[Impact::Inhibit System Recovery (T1490)](https://attack.mitre.org/techniques/T1490/)|The malware deletes volume shadow copies using vssadmin.exe [[1]](#1)| -|[Command and Control::Proxy (T1090)](https://attack.mitre.org/techniques/T1090/)|The malware tries to connect to I2P proxies [[1]](#1)| +|[Initial Access::Spearphishing Attachment (T1566.001)](https://attack.mitre.org/techniques/T1566/001/)| The malware file is sent as an attachment. [[1]](#1)| +|[Impact::Inhibit System Recovery (T1490)](https://attack.mitre.org/techniques/T1490/)|The malware deletes volume shadow copies using vssadmin.exe. [[1]](#1)| +|[Command and Control::Proxy (T1090)](https://attack.mitre.org/techniques/T1090/)|The malware tries to connect to I2P proxies. [[1]](#1)| +|[Impact::Data Encrypted for Impact (T1486)](https://attack.mitre.org/techniques/T1486/)|The malware encrypts files. [[1]](#1)| +|[Command and Control::Proxy (T1090)](https://attack.mitre.org/techniques/T1090/)|The malware tries to connect to I2P proxies. [[1]](#1)| + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Impact::Data Encrypted for Impact::Ransom Note (E1486.001)](../impact/data-encrypted-for-impact.md)|The malware launches Internet Explorer to show ransom notes [[1]](#1)| -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|The malware searches for user files before encrypting them [[1]](#1)| -|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|The malware injects code into a new svchost process [[1]](#1)| +|[Impact::Data Encrypted for Impact::Ransom Note (E1486.001)](../impact/data-encrypted-for-impact.md)|The malware launches Internet Explorer to show ransom notes. [[1]](#1)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|The malware searches for user files before encrypting them. [[1]](#1)| +|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|The malware injects code into a new svchost process. [[1]](#1)| + ## MBC Behaviors |Name|Use| |---|---| -|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|The malware sends a hash value generated from system information [[1]](#1)| -|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|The malware receives a public key from the C2 [[1]](#1)| +|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|The malware sends a hash value generated from system information. [[1]](#1)| +|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|The malware receives a public key from the C2. [[1]](#1)| ## Indicators of Compromise diff --git a/xample-malware/dark-comet.md b/xample-malware/dark-comet.md index af20fc2..a19f535 100644 --- a/xample-malware/dark-comet.md +++ b/xample-malware/dark-comet.md @@ -1,7 +1,7 @@
IDX0029X0008
Aliases
- + @@ -30,14 +30,14 @@ A Remote Access Trojan (RAT) that allows a user to control the system via a GUI. |Name|Use| |---|---| -|[Collection::Clipboard Data (T1115)](https://attack.mitre.org/techniques/T1115)|Read clipboard data (This capa rule had 8 matches) [[4]](#4) | -|[Defense Evasion::Hide Artifacts::Hidden Window (T1564.003)](https://attack.mitre.org/techniques/T1564/003)|Hide graphical window (This capa rule had 8 matches) [[4]](#4) | -|[Defense Evasion::Virtualization/Sandbox Evasion::User Activity Based Checks (T1497.002)](https://attack.mitre.org/techniques/T1497/002)|Check for unmoving mouse cursor (This capa rule had 1 match) [[4]](#4) | -|[Discovery::Application Window Discovery (T1010)](https://attack.mitre.org/techniques/T1010)|Enumerate gui resources (This capa rule had 3 matches) [[4]](#4) | -|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057)|Get process heap force flags (This capa rule had 1 match) [[4]](#4) | -|[Discovery::System Location Discovery (T1614)](https://attack.mitre.org/techniques/T1614)|Get geographical location (This capa rule had 5 matches) [[4]](#4) | -|[Discovery::System Location Discovery::System Language Discovery (T1614.001)](https://attack.mitre.org/techniques/T1614/001)|Get keyboard layout (This capa rule had 4 matches) [[4]](#4) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Parse PE header (This capa rule had 1 match) [[4]](#4) | +|[Collection::Clipboard Data (T1115)](https://attack.mitre.org/techniques/T1115)|The malware reads clipboard data. [[4]](#4)| +|[Defense Evasion::Hide Artifacts::Hidden Window (T1564.003)](https://attack.mitre.org/techniques/T1564/003)|The malware hides a graphical window. [[4]](#4)| +|[Defense Evasion::Virtualization/Sandbox Evasion::User Activity Based Checks (T1497.002)](https://attack.mitre.org/techniques/T1497/002)|The malware checks for an unmoving mouse cursor. [[4]](#4)| +|[Discovery::Application Window Discovery (T1010)](https://attack.mitre.org/techniques/T1010)|The malware enumerates GUI resources. [[4]](#4)| +|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057)|The malware gets process heap force flags. [[4]](#4)| +|[Discovery::System Location Discovery (T1614)](https://attack.mitre.org/techniques/T1614)|The malware gets the geographical location. [[4]](#4)| +|[Discovery::System Location Discovery::System Language Discovery (T1614.001)](https://attack.mitre.org/techniques/T1614/001)|The malware gets the keyboard layout. [[4]](#4)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|The malware parses PE headers. [[4]](#4)| See ATT&CK: [Dark Comet - Techniques Used](https://attack.mitre.org/software/S0334/). @@ -45,48 +45,51 @@ See ATT&CK: [Dark Comet - Techniques Used](https://attack.mitre.org/software/S03 |Name|Use| |---|---| -|[Collection::Keylogging (F0002)](../collection/keylogging.md)|DarkComet can capture keystrokes [[2]](#2) | -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|Adds several registry entries to enable automatic execution at startup [[2]](#2) | -|[Defense Evasion::Indicator Blocking (F0006)](../defense-evasion/indicator-blocking.md)|Can disable security center functions like anti-virus and firewall [[2]](#2) | -|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|Can download files from remote repository upon instruction [[2]](#2) | -|[Anti-Static Analysis::Software Packing (F0001)](../anti-static-analysis/software-packing.md)|Has the option to compress its payload using UPX or MPRESS [[2]](#2) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Can collect information about the computer, resources, and operating system version [[2]](#2) Get disk size (This capa rule had 1 match) [[4]](#4)| -|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|Log keystrokes via polling (This capa rule had 10 matches) [[4]](#4) | -|[Collection::Screen Capture::WinAPI (E1113.m01)](../collection/screen-capture.md)|Capture screenshot (This capa rule had 1 match) [[4]](#4) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 13 matches) [[4]](#4) | -|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|Get graphical window text (This capa rule had 2 matches) [[4]](#4) | -|[Impact::Clipboard Modification (E1510)](../impact/clipboard-modification.md)|Write clipboard data (This capa rule had 4 matches) [[4]](#4) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Get file version info (This capa rule had 1 match) [[4]](#4) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Accept command line arguments (This capa rule had 2 matches) [[4]](#4) | +|[Collection::Keylogging (F0002)](../collection/keylogging.md)|DarkComet can capture keystrokes. [[2]](#2)| +|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|DarkComet logs keystrokes via polling. [[4]](#4)| +|[Collection::Screen Capture (E1113)](../collection/screen-capture.md)|DarkComet can take screenshots of victim's computer. [[2]](#2)| +|[Collection::Screen Capture::WinAPI (E1113.m01)](../collection/screen-capture.md)|DarkComet captures screenshots. [[4]](#4)| +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|DarkComet adds several registry entries to enable automatic execution at startup. [[2]](#2)| +|[Defense Evasion::Indicator Blocking (F0006)](../defense-evasion/indicator-blocking.md)|DarkComet can disable security center functions like anti-virus and firewall. [[2]](#2)| +|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|DarkComet can download files from remote repository upon instruction. [[2]](#2)| +|[Anti-Static Analysis::Software Packing (F0001)](../anti-static-analysis/software-packing.md)|DarkComet has the option to compress its payload using UPX or MPRESS. [[2]](#2)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|DarkComet can collect information about the computer, resources, and operating system version and get disk size. [[2]](#2) [[4]](#4)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|DarkComet encodes data using XOR. [[4]](#4)| +|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|DarkComet gets graphical window text. [[4]](#4)| +|[Impact::Clipboard Modification (E1510)](../impact/clipboard-modification.md)|DarkComet writes clipboard data. [[4]](#4)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|DarkComet gets file version info. [[4]](#4)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|DarkComet accepts command line arguments. [[4]](#4)| + ## MBC Behaviors |Name|Use| |---|---| -|[Impact::Remote Access (B0022)](../impact/remote-access.md)|Allows an attacker to control the system via a GUI [[1]](#1) | -|[Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)](../anti-behavioral-analysis/debugger-detection.md)|Check for time delay via GetTickCount (This capa rule had 4 matches) [[4]](#4) | -|[Anti-Behavioral Analysis::Virtual Machine Detection::Human User Check (B0009.012)](../anti-behavioral-analysis/virtual-machine-detection.md)|Check for unmoving mouse cursor (This capa rule had 1 match) [[4]](#4) | -|[Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Encrypt data using RC4 PRGA (This capa rule had 3 matches) [[4]](#4) | -|[Data::Checksum::CRC32 (C0032.001)](../micro-behaviors/data/checksum.md)|Hash data with CRC32 (This capa rule had 5 matches) [[4]](#4) | -|[Data::Compression Library (C0060)](../micro-behaviors/data/compression-library.md)|Linked against ZLIB (This capa rule had 1 match) [[4]](#4) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 13 matches) [[4]](#4) | -|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Enumerate PE sections (This capa rule had 3 matches) [[4]](#4) | -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Contain an embedded PE file (This capa rule had 1 match) [[4]](#4) | -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 1 match) [[4]](#4) | -|[File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|Get file attributes (This capa rule had 2 matches) [[4]](#4) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 7 matches) [[4]](#4) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Writes Fileon Windows (This capa rule had 5 matches) [[4]](#4) | -|[Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Allocate RWX memory (This capa rule had 1 match) [[4]](#4) | -|[Operating System::Registry::Delete Registry Key (C0036.002)](../micro-behaviors/operating-system/registry.md)|Delete registry key (This capa rule had 1 match) [[4]](#4) | -|[Operating System::Registry::Delete Registry Value (C0036.007)](../micro-behaviors/operating-system/registry.md)|Delete registry value (This capa rule had 1 match) [[4]](#4) | -|[Operating System::Registry::Query Registry Key (C0036.005)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry key (This capa rule had 3 matches) [[4]](#4) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 6 matches) [[4]](#4) | -|[Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Set registry value (This capa rule had 1 match) [[4]](#4) | -|[Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Create process on Windows (This capa rule had 6 matches) [[4]](#4) | -|[Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|Create thread (This capa rule had 3 matches) [[4]](#4) | -|[Process::Resume Thread (C0054)](../micro-behaviors/process/resume-thread.md)|Resume thread (This capa rule had 2 matches) [[4]](#4) | -|[Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|Set thread local storage value (This capa rule had 1 match) [[4]](#4) | -|[Process::Suspend Thread (C0055)](../micro-behaviors/process/suspend-thread.md)|Suspend thread (This capa rule had 1 match) [[4]](#4) | +|[Impact::Remote Access (B0022)](../impact/remote-access.md)|DarkComet allows an attacker to control the system via a GUI. [[1]](#1)| +|[Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)](../anti-behavioral-analysis/debugger-detection.md)|DarkComet checks for a time delay via GetTickCount. [[4]](#4)| +|[Anti-Behavioral Analysis::Virtual Machine Detection::Human User Check (B0009.012)](../anti-behavioral-analysis/virtual-machine-detection.md)|DarkComet checks for an unmoving mouse cursor. [[4]](#4)| +|[Micro-Behaviors::Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|DarkComet encrypts data using RC4 PRGA. [[4]](#4)| +|[Micro-Behaviors::Data::Checksum::CRC32 (C0032.001)](../micro-behaviors/data/checksum.md)|DarkComet hashes data with CRC32. [[4]](#4)| +|[Micro-Behaviors::Data::Compression Library (C0060)](../micro-behaviors/data/compression-library.md)|DarkComet linked against ZLIB. [[4]](#4)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|DarkComet encodes data using XOR. [[4]](#4)| +|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|DarkComet enumerates PE sections. [[4]](#4)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|DarkComet contains an embedded PE file. [[4]](#4)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|DarkComet deletes files. [[4]](#4)| +|[Micro-Behaviors::File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|DarkComet gets file attributes. [[4]](#4)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|DarkComet reads files on Windows. [[4]](#4)| +|[Micro-Behaviors::File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|DarkComet writes Fileon Windows. [[4]](#4)| +|[Micro-Behaviors::Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|DarkComet allocates RWX memory. [[4]](#4)| +|[Micro-Behaviors::Operating System::Registry::Delete Registry Key (C0036.002)](../micro-behaviors/operating-system/registry.md)|DarkComet deletes registry keys. [[4]](#4)| +|[Micro-Behaviors::Operating System::Registry::Delete Registry Value (C0036.007)](../micro-behaviors/operating-system/registry.md)|DarkComet deletes registry values. [[4]](#4)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Key (C0036.005)](../micro-behaviors/operating-system/registry.md)|DarkComet queries or enumerates registry keys. [[4]](#4)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|DarkComet queries or enumerates registry values. [[4]](#4)| +|[Micro-Behaviors::Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|DarkComet sets registry values. [[4]](#4)| +|[Micro-Behaviors::Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|DarkComet creates a process on Windows. [[4]](#4)| +|[Micro-Behaviors::Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|DarkComet creates a thread. [[4]](#4)| +|[Micro-Behaviors::Process::Resume Thread (C0054)](../micro-behaviors/process/resume-thread.md)|DarkComet resumes a thread. [[4]](#4)| +|[Micro-Behaviors::Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|DarkComet set thread local storage values. [[4]](#4)| +|[Micro-Behaviors::Process::Suspend Thread (C0055)](../micro-behaviors/process/suspend-thread.md)|DarkComet suspends threads. [[4]](#4)| + ## Indicators of Compromise @@ -103,4 +106,3 @@ SHA256 Hashes [3] https://bazaar.abuse.ch/browse/signature/DarkComet/ [4] capa v4.0, analyzed at MITRE on 10/12/2022 - diff --git a/xample-malware/dnschanger.md b/xample-malware/dnschanger.md index fb4b4e7..d330c1a 100644 --- a/xample-malware/dnschanger.md +++ b/xample-malware/dnschanger.md @@ -1,7 +1,7 @@
IDX0004X0009
Aliases
- + @@ -24,37 +24,38 @@ # DNSChanger -Used to change DNS settings to generate fraudulent advertising revenue. +DNSChanger is used to change DNS settings to generate fraudulent advertising revenue. ## ATT&CK Techniques |Name|Use| |---|---| -|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Set file attributes (This capa rule had 1 match) [[3]](#3) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Access PE header (This capa rule had 3 matches) [[3]](#3) | +|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|DNSChanger sets file attributes. [[3]](#3)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|DNSChanger accesses PE headers. [[3]](#3)| ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Impact::Generate Traffic from Victim::Advertisement Replacement Fraud (E1643)](../impact/generate-traffic-from-victim.md)|Alters DNS server settings to route to a rogue DNS server for the purpose of click hijacking. [[1]](#1) | -|[Defense Evasion::Disable or Evade Security Tools (F0004)](../defense-evasion/disable-or-evade-security-tools.md)|Prevents the infected system from installing anti-virus software updates. [[1]](#1) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 1 match) [[3]](#3) | -|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|Attach user process memory (This capa rule had 1 match) [[3]](#3) | +|[Impact::Generate Traffic from Victim::Advertisement Replacement Fraud (E1643.m02)](../impact/generate-traffic-from-victim.md)|The malware alters DNS server settings to route to a rogue DNS server for the purpose of click hijacking. [[1]](#1)| +|[Defense Evasion::Disable or Evade Security Tools (F0004)](../defense-evasion/disable-or-evade-security-tools.md)|DNSChanger prevents the infected system from installing anti-virus software updates. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|DNSChanger encodes data using XOR. [[3]](#3)| +|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|DNSChanger attaches user process memory. [[3]](#3)| ## MBC Behaviors |Name|Use| |---|---| -|[Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Encrypt data using RC4 PRGA (This capa rule had 1 match) [[3]](#3) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 1 match) [[3]](#3) | -|[File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|Get file attributes (This capa rule had 1 match) [[3]](#3) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 3 matches) [[3]](#3) | -|[File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|Set file attributes (This capa rule had 1 match) [[3]](#3) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Writes Fileon Windows (This capa rule had 2 matches) [[3]](#3) | -|[Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Allocate RWX memory (This capa rule had 2 matches) [[3]](#3) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 1 match) [[3]](#3) | -|[Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Set registry value (This capa rule had 2 matches) [[3]](#3) | +|[Micro-Behaviors::Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|DNSChanger encrypts data using RC4 PRGA. [[3]](#3)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|DNSChanger encodes data using XOR. [[3]](#3)| +|[Micro-Behaviors::File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|DNSChanger gets file attributes. [[3]](#3)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|DNSChanger reads files on Windows. [[3]](#3)| +|[Micro-Behaviors::File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|DNSChanger sets file attributes. [[3]](#3)| +|[Micro-Behaviors::File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|DNSChanger writes Fileon Windows. [[3]](#3)| +|[Micro-Behaviors::Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|DNSChanger allocates RWX memory. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|DNSChanger queries or enumerates registry values. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|DNSChanger sets registry keys. [[3]](#3)| + ## Indicators of Compromise @@ -69,4 +70,3 @@ SHA256 Hashes [2] https://www.joesandbox.com/analysis/258032/0/html [3] capa v4.0, analyzed at MITRE on 10/12/2022 - diff --git a/xample-malware/emotet.md b/xample-malware/emotet.md index f679a57..98279aa 100644 --- a/xample-malware/emotet.md +++ b/xample-malware/emotet.md @@ -1,7 +1,7 @@
IDX0005X0010
Aliases
- + @@ -30,30 +30,32 @@ Emotet is a banking trojan. [[1]](#1) |Name|Use| |---|---| -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Parse pe header (this capa rule had 1 match) [[6]](#6) | +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Emotet parses PE headers. [[6]](#6)| ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Anti-Static Analysis::Software Packing::Custom Compression (F0001.005)](../anti-static-analysis/software-packing.md)|Emotet uses custom packers which first decrypt the loaders and the loaders decrypt and load emotet's main payloads [[2]](#2) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Collects information related to os, processes, and sometimes mail client information and sends it to c2 [[2]](#2) | -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|To start itself at system boot, emotet adds the downloaded payload to the registry to maintain persistence [[1]](#1) | -|[Impact::Clipboard Modification (E1510)](../impact/clipboard-modification.md)|Write clipboard data (this capa rule had 1 match) [[6]](#6) | +|[Anti-Static Analysis::Software Packing::Custom Compression (F0001.005)](../anti-static-analysis/software-packing.md)|Emotet uses custom packers which first decrypt the loaders, and then the loaders decrypt and load Emotet's main payloads. [[2]](#2)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Emotet collects information related to OS, processes, and sometimes mail client information and sends it to C2. [[2]](#2)| +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|To start itself at system boot, Emotet adds the downloaded payload to the registry to maintain persistence. [[1]](#1)| +|[Impact::Clipboard Modification (E1510)](../impact/clipboard-modification.md)|Emotet writes clipboard data. [[6]](#6)| + ## MBC Behaviors |Name|Use| |---|---| -|[Anti-Static Analysis::Executable Code Obfuscation::Junk Code Insertion (B0032.007)](../anti-static-analysis/executable-code-obfuscation.md)|Emotet macros are heavily obfuscated with junk functions and string substitutions [[1]](#1) | -|[Micro-objective::Cryptography::Encrypt Data::RSA (C0027.011)](../micro-behaviors/cryptography/encrypt-data.md)|Emotet uses rsa to encrypt network traffic to its c2 [[2]](#2) | -|[Discovery::Analysis Tool Discovery::Process detection - Debuggers (B0013.002)](../discovery/analysis-tool-discovery.md)|If it recieves a response from the c2 server stating a debugging-related tool is in the list of running processes, it recieves an "upgrade" command which calls the shellexecutew function and exits [[3]](#3) | -|[Anti-Behavioral Analysis::Virtual Machine Detection::Guest Process Testing (B0009.010)](../anti-behavioral-analysis/virtual-machine-detection.md)|Emotet checks for various processes that are associated with various virtual machines by comparing hash values of the process names with the hash values of the list of running process names [[4]](#4) | -|[Command and Control::C2 Communication::Request Email Address List (B0030.010)](../command-and-control/c2-communication.md)| new email addresses are collected automatically from the victim's address books [[4]](#4) | -|[Execution::Send Email (B0020)](../execution/send-email.md)|Spam email with the emotet loader is sent automatically [[4]](#4) | -|[Communication::HTTP Communication::Create Request (C0002.012)](../micro-behaviors/communication/http-communication.md)|Create http request (this capa rule had 1 match) [[6]](#6) | -|[Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Encrypt data using rc4 prga (this capa rule had 4 matches) [[6]](#6) | -|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Enumerate pe sections (this capa rule had 1 match) [[6]](#6) | +|[Anti-Static Analysis::Executable Code Obfuscation::Junk Code Insertion (B0032.007)](../anti-static-analysis/executable-code-obfuscation.md)|Emotet macros are heavily obfuscated with junk functions and string substitutions. [[1]](#1)| +|[Micro-behaviors::Cryptography::Encrypt Data::RSA (C0027.011)](../micro-behaviors/cryptography/encrypt-data.md)|Emotet uses RSA to encrypt network traffic to its C2. [[2]](#2)| +|[Discovery::Analysis Tool Discovery::Process detection - Debuggers (B0013.002)](../discovery/analysis-tool-discovery.md)|If it receives a response from the C2 server stating a debugging-related tool is in the list of running processes, it receives an "upgrade" command which calls the ShellExecuteW function and exits. [[3]](#3)| +|[Anti-Behavioral Analysis::Virtual Machine Detection::Guest Process Testing (B0009.010)](../anti-behavioral-analysis/virtual-machine-detection.md)|Emotet checks for various processes that are associated with various virtual machines by comparing hash values of the process names with the hash values of the list of running process names. [[4]](#4)| +|[Command and Control::C2 Communication::Request Email Address List (B0030.010)](../command-and-control/c2-communication.md)|New email addresses are collected automatically from the victim's address books. [[4]](#4)| +|[Execution::Send Email (B0020)](../execution/send-email.md)|Spam email with the Emotet loader is sent automatically. [[4]](#4)| +|[Micro-Behaviors::Communication::HTTP Communication::Create Request (C0002.012)](../micro-behaviors/communication/http-communication.md)|Emotet creates a HTTP request. [[6]](#6)| +|[Micro-Behaviors::Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Emotet encrypts data using RC4 PRGA. [[6]](#6)| +|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Emotet enumerates PE sections. [[6]](#6)| + ## Indicators of Compromise diff --git a/xample-malware/evilbunny.md b/xample-malware/evilbunny.md index 0f5d32f..c05df9d 100644 --- a/xample-malware/evilbunny.md +++ b/xample-malware/evilbunny.md @@ -2,7 +2,7 @@
IDX0028X0011
Aliases
- + @@ -25,7 +25,7 @@ # EvilBunny -C++ malware designed to be an execution platform for Lua scripts +The malware is written in C++ and designed to be an execution platform for Lua scripts. ## ATT&CK Techniques @@ -35,15 +35,15 @@ See ATT&CK: [EvilBunny - Techniques Used](https://attack.mitre.org/software/S039 |Name|Use| |---|---| -|[Execution::Command and Scripting Interpreter (E1049)](../execution/command-and-scripting-interpreter.md)|EvilBunny executes Lua scripts [[1]](#1)| -|[Command and Control::C2 Communication (B0030)](../command-and-control/c2-communication.md)|EvilBunny communicates C2 via HTTP [[1]](#1)| +|[Execution::Command and Scripting Interpreter (E1049)](../execution/command-and-scripting-interpreter.md)|EvilBunny executes Lua scripts. [[1]](#1)| +|[Command and Control::C2 Communication (B0030)](../command-and-control/c2-communication.md)|EvilBunny communicates C2 via HTTP. [[1]](#1)| ## MBC Behaviors |Name|Use| |---|---| -|[Anti-Behavioral Analysis::Sandbox Detection (B0007)](../anti-behavioral-analysis/sandbox-detection.md)|EvilBunny hooks time retrieval APIs and calls each API twice to calculate a delta. Execution aborts depending on the delta value [[1]](#1)| -|[Defense Evasion::Polymorphic Code (B0029)](../defense-evasion/polymorphic-code.md)|EvilBunny utilizes Lua scripts to exhibit polymorphism [[1]](#1)| +|[Anti-Behavioral Analysis::Sandbox Detection (B0007)](../anti-behavioral-analysis/sandbox-detection.md)|EvilBunny hooks time retrieval APIs and calls each API twice to calculate a delta. Execution aborts depending on the delta value. [[1]](#1)| +|[Defense Evasion::Polymorphic Code (B0029)](../defense-evasion/polymorphic-code.md)|EvilBunny utilizes Lua scripts to exhibit polymorphism. [[1]](#1)| ## Indicators of Compromise diff --git a/xample-malware/gamut.md b/xample-malware/gamut.md index a9e9507..5ff5282 100644 --- a/xample-malware/gamut.md +++ b/xample-malware/gamut.md @@ -1,7 +1,7 @@
IDX0036X0012
Aliases
- + @@ -24,58 +24,61 @@ # Gamut -A spamming botnet. +Gamut is a spamming botnet. ## ATT&CK Techniques |Name|Use| |---|---| +|[Command and Control::Application Layer Protocol::Web Protocols (T1071.001)](https://attack.mitre.org/techniques/T1071/001/)|The malware uses HTTP for command and control. [[1]](#1)| +|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Gamut sets file attributes. [[3]](#3)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Gamut links functions at runtime on Windows. [[3]](#3)| -|[Command and Control::Application Layer Protocol::Web Protocols (T1071.001)](https://attack.mitre.org/techniques/T1071/001/)|The malware uses HTTP for command and control [[1]](#1) | -|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Set file attributes (This capa rule had 2 matches) [[3]](#3) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Link function at runtime on Windows (This capa rule had 1 match) [[3]](#3) | ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|The malware adds a registry key [[1]](#1) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 1 match) [[3]](#3) | -|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|Get graphical window text (This capa rule had 1 match) [[3]](#3) | -|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|The malware receives files from C2 [[1]](#1) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Get common file path (This capa rule had 5 matches) [[3]](#3) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Query environment variable (This capa rule had 1 match) [[3]](#3) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Accept command line arguments (This capa rule had 1 match) [[3]](#3) | +|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|The malware adds a registry key. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Gamut encodes data using XOR. [[3]](#3)| +|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|Gamut gets a graphical window text. [[3]](#3)| +|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|The malware receives files from C2. [[1]](#1)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Gamut gets common file paths. [[3]](#3)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Gamut queries environment variables. [[3]](#3)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Gamut accepts command line arguments. [[3]](#3)| + ## MBC Behaviors |Name|Use| |---|---| -|[Execution::Send Email (B0020)](../execution/send-email.md)|Gamut probes the infected system's SMTP port 25 by sending a test SMTP transaction to mail.ru and hotmail.com. If port 25 is open, the bot requests the spam template and email list, which it uses to send spam. [[1]](#1) | -|[Anti-Behavioral-Analysis::Debugger Detection::Interruption (B0001.006)](../anti-behavioral-analysis/debugger-detection.md)|The malware detects debuggers using an INT 03h trap [[1]](#1) | -|[Anti-Behavioral-Analysis::Debugger Detection::IsDebuggerPresent (B0001.008)](../anti-behavioral-analysis/debugger-detection.md)|The malware detects debuggers using IsDebuggerPresent [[1]](#1) | -|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|The malware receives data from C2 [[1]](#1) | -|[Impact::Spamming (B0039)](../impact/spamming.md)|If port 25 is open, the bot uses a spam template and email list to send spam. [[1]](#1) | -|[Data::Checksum::CRC32 (C0032.001)](../micro-behaviors/data/checksum.md)|Hash data with CRC32 (This capa rule had 1 match) [[3]](#3) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 1 match) [[3]](#3) | +|[Execution::Send Email (B0020)](../execution/send-email.md)|Gamut probes the infected system's SMTP port 25 by sending a test SMTP transaction to mail.ru and hotmail.com. If port 25 is open, the bot requests the spam template and email list, which it uses to send spam. [[1]](#1)| +|[Anti-Behavioral-Analysis::Debugger Detection::Interruption (B0001.006)](../anti-behavioral-analysis/debugger-detection.md)|The malware detects debuggers using an INT 03h trap. [[1]](#1)| +|[Anti-Behavioral-Analysis::Debugger Detection::IsDebuggerPresent (B0001.008)](../anti-behavioral-analysis/debugger-detection.md)|The malware detects debuggers using IsDebuggerPresent. [[1]](#1)| +|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|The malware receives data from C2. [[1]](#1)| +|[Command and Control::C2 Communication::Server to Client File Transfer (B0030.003)](../command-and-control/c2-communication.md)|The malware receives files from C2. [[1]](#1)| +|[Impact::Spamming (B0039)](../impact/spamming.md)|If port 25 is open, the bot uses a spam template and email list to send spam. [[1]](#1)| +|[Micro-Behaviors::Data::Checksum::CRC32 (C0032.001)](../micro-behaviors/data/checksum.md)|Gamut hashes data with CRC32. [[3]](#3)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Gamut encodes data using XOR. [[3]](#3)| |[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Enumerate PE sections (This capa rule had 1 match) [[3]](#3) | -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Contain an embedded PE file (This capa rule had 1 match) [[3]](#3) | -|[File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|Create directory (This capa rule had 1 match) [[3]](#3) | -|[File System::Delete Directory (C0048)](../micro-behaviors/file-system/delete-directory.md)|Delete directory (This capa rule had 1 match) [[3]](#3) | -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 4 matches) [[3]](#3) | -|[File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|Get file attributes (This capa rule had 10 matches) [[3]](#3) | -|[File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|Move file (This capa rule had 1 match) [[3]](#3) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 2 matches) [[3]](#3) | -|[File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|Set file attributes (This capa rule had 2 matches) [[3]](#3) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Writes file on Windows (This capa rule had 3 matches) [[3]](#3) | -|[Operating System::Registry::Delete Registry Key (C0036.002)](../micro-behaviors/operating-system/registry.md)|Delete registry key (This capa rule had 3 matches) [[3]](#3) | -|[Operating System::Registry::Delete Registry Value (C0036.007)](../micro-behaviors/operating-system/registry.md)|Delete registry value (This capa rule had 1 match) [[3]](#3) | -|[Operating System::Registry::Query Registry Key (C0036.005)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry key (This capa rule had 1 match) [[3]](#3) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 2 matches) [[3]](#3) | -|[Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Set registry value (This capa rule had 3 matches) [[3]](#3) | -|[Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Create process on Windows (This capa rule had 4 matches) [[3]](#3) | -|[Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|Set thread local storage value (This capa rule had 1 match) [[3]](#3) | +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Gamut contains an embedded PE file. [[3]](#3)| +|[Micro-Behaviors::File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|Gamut creates directories. [[3]](#3)| +|[Micro-Behaviors::File System::Delete Directory (C0048)](../micro-behaviors/file-system/delete-directory.md)|Gamut deletes directories. [[3]](#3)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Gamut deletes file. [[3]](#3)| +|[Micro-Behaviors::File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|Gamut gets file attributes. [[3]](#3)| +|[Micro-Behaviors::File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|Gamut moves files. [[3]](#3)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Gamut reads files on Windows. [[3]](#3)| +|[Micro-Behaviors::File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|Gamut sets file attributes. [[3]](#3)| +|[Micro-Behaviors::File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Gamut writes files on Windows. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Delete Registry Key (C0036.002)](../micro-behaviors/operating-system/registry.md)|Gamut deletes registry keys. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Delete Registry Value (C0036.007)](../micro-behaviors/operating-system/registry.md)|Gamut deletes registry values. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Key (C0036.005)](../micro-behaviors/operating-system/registry.md)|Gamut queries or enumerates registry keys. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Gamut queries or enumerates registry values. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Gamut sets registry values. [[3]](#3)| +|[Micro-Behaviors::Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Gamut creates processes on Windows. [[3]](#3)| +|[Micro-Behaviors::Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|Gamut sets thread local storage values. [[3]](#3)| + ## Indicators of Compromise diff --git a/xample-malware/geneio.md b/xample-malware/geneio.md index 449041a..f02ab17 100644 --- a/xample-malware/geneio.md +++ b/xample-malware/geneio.md @@ -2,7 +2,7 @@
IDX0006X0013
Aliases
- + @@ -41,20 +41,21 @@ Next, the program changes the default search engine and homepage to the domain * The program then installs the browser extension *~/Library/Safari/Extensions/Omnibar.safariextz*. -When the user inputs a search query it will appear to be carried out using Google Search but the results will be from *genieo.com*. +When the user inputs a search query, it will appear to be carried out using Google Search, but the results will be from *genieo.com*. ## ATT&CK Techniques |Name|Use| |---|---| -|[Persistence::Browser Extensions (T1176)](https://attack.mitre.org/techniques/T1176/)|Geneio installs Safari Extensions that are adware [[1]](#1)| +|[Persistence::Browser Extensions (T1176)](https://attack.mitre.org/techniques/T1176/)|Geneio installs Safari Extensions that are adware. [[1]](#1)| ## MBC Behaviors |Name|Use| |---|---| -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Geneio installs the browser extension ~/Library/Safari/Extensions/Omnibar.safariextz. It also creates app files. [[1]](#1)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Malware tricks OS X keychain to create application files. Geneio installs the browser extension ~/Library/Safari/Extensions/Omnibar.safariextz. It also creates the app files listed in the description above. [[1]](#1)| + ## Indicators of Compromise diff --git a/xample-malware/gobotkr.md b/xample-malware/gobotkr.md index b603026..8a7bbc2 100644 --- a/xample-malware/gobotkr.md +++ b/xample-malware/gobotkr.md @@ -1,7 +1,7 @@
IDX0007X0014
Aliases
- + @@ -24,7 +24,7 @@ # GoBotKR -Modified version of a publicly available backdoor name GoBot2. Modifications are mainly evasion techniques specific to South Korea. [[1]](#1) +GoBotKR is a modified version of a publicly available backdoor, GoBot2. The modifications to GoBot2 are mainly evasion techniques specific to South Korea. [[1]](#1) From [[1]](#1), “The malware installs two instances of itself on the system. The second instance (watchdog) monitors whether the first instance is still active and reinstalls it if it has been removed from the system.” @@ -33,56 +33,60 @@ From [[1]](#1), “The malware installs two instances of itself on the system. T |Name|Use| |---|---| -|[Initial Access::Drive-by Compromise (T1189)](https://attack.mitre.org/techniques/T1189/)|GoBotKR has been distributed through torrent file-sharing websites to South Korean victims, using games or Korean movie/TV series as a lure. [[1]](#1) | -|[Persistence::Scheduled Task (T1053)](https://attack.mitre.org/techniques/T1053/)|GoBotKR schedules a task that adds a registry run key to establish malware persistence. [[1]](#1) | -|[Privilege Escalation::Abuse Elevation Control Mechanism::Bypass User Account Control (T1548.002)](https://attack.mitre.org/techniques/T1548/002/)|GoBotKR attempts to bypass UAC using Registry Hijacking. [[1]](#1) | -|[Defense Evasion::Deobfuscate/Decode Files or Information (T1140)](https://attack.mitre.org/techniques/T1140/)|GoBotKR has used base64 to obfuscate strings, commands and files. [[1]](#1) | -|[Defense Evasion::Indicator Removal (T1070)](https://attack.mitre.org/techniques/T1070/)|GoBotKR removes the Zone identifier from the ADS (Alternate Data Streams) of the file, to conceal the fact the file has been downloaded from the internet. [[1]](#1) | -|[Defense Evasion::Masquerading (T1036)](https://attack.mitre.org/techniques/T1036/)| GoBotKR uses filenames and registry key names associated with legitimate software. [[1]](#1) | -|[Discovery::Software Discovery::Security Software Discovery (T1518.001)](https://attack.mitre.org/techniques/T1518/001/)|GoBotKR checks for processes associated with security products and debugging tools, and terminates itself if any are detected. It can enumerate installed antivirus software using the wmic command. [[1]](#1) | -|[Discovery::System Network Configuration Discovery (T1016)](https://attack.mitre.org/techniques/T1016/)|GoBotKR uses netsh and ipconfig to collect information about the network configuration. It has used Naver and Daum portals to obtain the client IP address. [[1]](#1) | -|[Discovery::System Owner/User Discovery (T1033)](https://attack.mitre.org/techniques/T1033/)|GoBotKR uses whoami to obtain information about the victimized user. It runs tests to determine the privilege level of the compromised user. [[1]](#1) | -|[Discovery::System Time Discovery (T1124)](https://attack.mitre.org/techniques/T1124/)| GoBotKR can obtain the date and time of the compromised system. [[1]](#1) | -|[Lateral Movement::Ingress Tool Transfer (T1105)](https://attack.mitre.org/techniques/T1105/)| GoBotKR attempts to copy itself into public folders of cloud storage services (Google Drive, Dropbox, OneDrive). [[1]](#1) | -|[Lateral Movement::Replication Through Removable Media (T1091)](https://attack.mitre.org/techniques/T1091/)|GoBotKR can drop itself onto removable media and relies on Autorun to execute the malicious file when a user opens the removable media on another system. [[1]](#1) | -|[Command and Control::Proxy (T1090)](https://attack.mitre.org/techniques/T1090/)|GoBotKR can be used as a proxy server. [[1]](#1) | -|[Command and Control::Data Encoding (T1132)](https://attack.mitre.org/techniques/T1132/)|The communication with the C&C server is base64 encoded. [[1]](#1) | -|[Command and Control::Application Layer Protocol (T1071)](https://attack.mitre.org/techniques/T1071/)|GoBotKR uses HTTP or HTTPS for C&C. [[1]](#1) | -|[Command and Control::Non-Standard Port (T1571)](https://attack.mitre.org/techniques/T1571/)|GoBotKR uses non-standard ports, such as 6446, 6556 and 7777, for C&C. [[1]](#1) | +|[Initial Access::Drive-by Compromise (T1189)](https://attack.mitre.org/techniques/T1189/)|GoBotKR has been distributed through torrent file-sharing websites to South Korean victims, using games or Korean movie/TV series as a lure. [[1]](#1)| +|[Persistence::Scheduled Task (T1053)](https://attack.mitre.org/techniques/T1053/)|GoBotKR schedules a task that adds a registry run key to establish malware persistence. [[1]](#1)| +|[Privilege Escalation::Abuse Elevation Control Mechanism::Bypass User Account Control (T1548.002)](https://attack.mitre.org/techniques/T1548/002/)|GoBotKR attempts to bypass UAC using Registry Hijacking. [[1]](#1)| +|[Defense Evasion::Deobfuscate/Decode Files or Information (T1140)](https://attack.mitre.org/techniques/T1140/)|GoBotKR has used base64 to obfuscate strings, commands and files. [[1]](#1)| +|[Defense Evasion::Indicator Removal (T1070)](https://attack.mitre.org/techniques/T1070/)|GoBotKR removes the Zone identifier from the ADS (Alternate Data Streams) of the file, to conceal the fact the file has been downloaded from the internet. [[1]](#1)| +|[Defense Evasion::Masquerading (T1036)](https://attack.mitre.org/techniques/T1036/)|GoBotKR uses filenames and registry key names associated with legitimate software. [[1]](#1)| +|[Discovery::Software Discovery::Security Software Discovery (T1518.001)](https://attack.mitre.org/techniques/T1518/001/)|GoBotKR checks for processes associated with security products and debugging tools, and terminates itself if any are detected. It can enumerate installed antivirus software using the wmic command. [[1]](#1)| +|[Discovery::System Information Discovery (T1082)](https://attack.mitre.org/techniques/T1082/)|GoBotKR uses wmic, systeminfo and ver commands to collect information about the system and the installed software. [[1]](#1)| +|[Discovery::System Network Configuration Discovery (T1016)](https://attack.mitre.org/techniques/T1016/)|GoBotKR uses netsh and ipconfig to collect information about the network configuration. It has used Naver and Daum portals to obtain the client IP address. [[1]](#1)| +|[Discovery::System Owner/User Discovery (T1033)](https://attack.mitre.org/techniques/T1033/)|GoBotKR uses whoami to obtain information about the victimized user. It runs tests to determine the privilege level of the compromised user. [[1]](#1)| +|[Discovery::System Time Discovery (T1124)](https://attack.mitre.org/techniques/T1124/)|GoBotKR can obtain the date and time of the compromised system. [[1]](#1)| +|[Lateral Movement::Ingress Tool Transfer (T1105)](https://attack.mitre.org/techniques/T1105/)| GoBotKR attempts to copy itself into public folders of cloud storage services (Google Drive, Dropbox, OneDrive). [[1]](#1)| +|[Lateral Movement::Replication Through Removable Media (T1091)](https://attack.mitre.org/techniques/T1091/)|GoBotKR can drop itself onto removable media and relies on Autorun to execute the malicious file when a user opens the removable media on another system. [[1]](#1)| +|[Command and Control::Proxy (T1090)](https://attack.mitre.org/techniques/T1090/)|GoBotKR can be used as a proxy server. [[1]](#1)| +|[Command and Control::Data Encoding (T1132)](https://attack.mitre.org/techniques/T1132/)|The communication with the C&C server is Base64 encoded. [[1]](#1)| +|[Command and Control::Ingress Tool Transfer (T1105)](https://attack.mitre.org/techniques/T1105/)|GoBotKR can download additional files and update itself. [[1]](#1)| +|[Command and Control::Application Layer Protocol (T1071)](https://attack.mitre.org/techniques/T1071/)|GoBotKR uses HTTP or HTTPS for C&C. [[1]](#1)| +|[Command and Control::Non-Standard Port (T1571)](https://attack.mitre.org/techniques/T1571/)|GoBotKR uses non-standard ports, such as 6446, 6556 and 7777, for C&C. [[1]](#1)| + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|GoBotKR uses cmd.exe to execute commands. [[1]](#1) | -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)| GoBotKR installs itself under registry run keys to establish persistence. [[1]](#1) | -|[Defense Evasion::Hidden Files and Directories (F0005)](../defense-evasion/hidden-files-and-directories.md)| GoBotKR stores itself in a file with Hidden and System attributes. [[1]](#1) | -|[Defense Evasion::Obfuscated Files or Information (E1027)](../defense-evasion/obfuscated-files-or-information.md)|GoBotKR uses base64 to obfuscate strings, commands and files. [[1]](#1) | -|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|GoBotKR can modify registry keys to disable Task Manager, Registry Editor and Command Prompt. [[1]](#1) | -|[Collection::Screen Capture (E1113)](../collection/screen-capture.md)| GoBotKR is capable of capturing screenshots. [[1]](#1) | -|[Execution::User Execution (E1204)](../execution/user-execution.md)| GoBotKR makes their malware look like the torrent content that the user intended to download, in order to entice a user to click on it. [[1]](#1) | +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|GoBotKR uses cmd.exe to execute commands. [[1]](#1)| +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|GoBotKR installs itself under registry run keys to establish persistence. [[1]](#1)| +|[Defense Evasion::Hidden Files and Directories (F0005)](../defense-evasion/hidden-files-and-directories.md)|GoBotKR stores itself in a file with Hidden and System attributes. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information (E1027)](../defense-evasion/obfuscated-files-or-information.md)|GoBotKR uses base64 to obfuscate strings, commands and files. [[1]](#1)| +|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|GoBotKR can modify registry keys to disable Task Manager, Registry Editor and Command Prompt. [[1]](#1)| +|[Collection::Screen Capture (E1113)](../collection/screen-capture.md)|GoBotKR is capable of capturing screenshots. [[1]](#1)| +|[Execution::User Execution (E1204)](../execution/user-execution.md)|GoBotKR makes their malware look like the torrent content that the user intended to download, in order to entice a user to click on it. [[1]](#1)| |[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|GoBotKR can download additional files and update itself. [[1]](#1) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|GoBotKR uses wmic, systeminfo and ver commands to collect information about the system and the installed software. [[1]](#1) query environment variable (This capa rule had 2 matches) [[2]](#2) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Check if file exists (This capa rule had 1 match) [[2]](#2) | +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|GoBotKR uses wmic, systeminfo, and ver commands to collect information about the system and the installed software and queries environment variables. [[1]](#1) [[2]](#2)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|GoBotKR checks if a file exists. [[2]](#2)| + ## MBC Behaviors |Name|Use| |---|---| -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|GoBotKR reinstalls its running instance if it is removed. [[1]](#1) | -|[Anti-Behavioral-Analysis::Sandbox Detection (B0007)](../anti-behavioral-analysis/sandbox-detection.md)|GoBotKR performs several checks on the compromised machine to avoid being emulated or executed in a sandbox. [[1]](#1) | -|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|GoBotKR receives data from the C2 [[1]](#1) | -|[Impact::Denial of Service (B0033)](../impact/denial-of-service.md)|GoBotKR has been used to execute endpoint DDoS attacks – for example, TCP Flood or SYN Flood. [[1]](#1) | -|[Impact::Resource Hijacking (B0018)](../impact/resource-hijacking.md)|GoBotKR can use the compromised computer’s network bandwidth to seed torrents or execute DDoS. [[1]](#1) | -|[Command And Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|Receive data (This capa rule had 2 matches) [[2]](#2) | -|[File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|Copy file (This capa rule had 1 match) [[2]](#2) | -|[File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|Create directory (This capa rule had 1 match) [[2]](#2) | -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 1 match) [[2]](#2) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 1 match) [[2]](#2) | -|[Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Create process on Windows (This capa rule had 4 matches) [[2]](#2) | -|[Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|Create thread (This capa rule had 2 matches) [[2]](#2) | -|[Process::Suspend Thread (C0055)](../micro-behaviors/process/suspend-thread.md)|Suspend thread (This capa rule had 2 matches) [[2]](#2) | -|[Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Terminate process (This capa rule had 1 match) [[2]](#2) | +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|GoBotKR reinstalls its running instance if it is removed. [[1]](#1)| +|[Anti-Behavioral-Analysis::Sandbox Detection (B0007)](../anti-behavioral-analysis/sandbox-detection.md)|GoBotKR performs several checks on the compromised machine to avoid being emulated or executed in a sandbox. [[1]](#1)| +|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|GoBotKR receives data from the C2. [[1]](#1) [[2]](#2)| +|[Impact::Denial of Service (B0033)](../impact/denial-of-service.md)|GoBotKR has been used to execute endpoint DDoS attacks – for example, TCP Flood or SYN Flood. [[1]](#1)| +|[Impact::Resource Hijacking (B0018)](../impact/resource-hijacking.md)|GoBotKR can use the compromised computer’s network bandwidth to seed torrents or execute DDoS. [[1]](#1)| +|[Micro-Behaviors::File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|GoBotKR copies files. [[2]](#2)| +|[Micro-Behaviors::File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|GoBotKR creates directories. [[2]](#2)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|GoBotKR deletes files. [[2]](#2)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|GoBotKR queries or enumerates registry values. [[2]](#2)| +|[Micro-Behaviors::Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|GoBotKR creates processes on Windows. [[2]](#2)| +|[Micro-Behaviors::Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|GoBotKR creates threads. [[2]](#2)| +|[Micro-Behaviors::Process::Suspend Thread (C0055)](../micro-behaviors/process/suspend-thread.md)|GoBotKR suspends threads. [[2]](#2)| +|[Micro-Behaviors::Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|GoBotKR terminates processes. [[2]](#2)| + ## Indicators of Compromise diff --git a/xample-malware/gravity-rat.md b/xample-malware/gravity-rat.md index 14341ab..c26cb25 100644 --- a/xample-malware/gravity-rat.md +++ b/xample-malware/gravity-rat.md @@ -1,7 +1,7 @@
IDX0027X0015
Aliases
- + @@ -24,14 +24,14 @@ # GravityRAT -Evades detection by checking current CPU temperature. +GravityRAT evades detection by checking current CPU temperature. ## ATT&CK Techniques |Name|Use| |---|---| -|[Discovery::Account Discovery (T1087)](https://attack.mitre.org/techniques/T1087)|Get session user name (This capa rule had 1 match) [[4]](#4) | +|[Discovery::Account Discovery (T1087)](https://attack.mitre.org/techniques/T1087)|GravityRAT gets session user name. [[4]](#4)| See ATT&CK: [GravityRAT - Techniques Used](https://attack.mitre.org/software/S0237/). @@ -39,26 +39,28 @@ See ATT&CK: [GravityRAT - Techniques Used](https://attack.mitre.org/software/S02 |Name|Use| |---|---| -|[Defense Evasion::Hijack Execution Flow::Abuse Windows Function Calls (F0015.006)](../defense-evasion/hijack-execution-flow.md)|Abuses Microsoft's Dynamic Data Exchange (DDE) protocol [[2]](#2) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Enumerate files on windows (This capa rule had 3 matches) [[4]](#4) | +|[Defense Evasion::Hijack Execution Flow::Abuse Windows Function Calls (F0015.006)](../defense-evasion/hijack-execution-flow.md)|GravityRAT abuses Microsoft's Dynamic Data Exchange (DDE) protocol. [[2]](#2)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|GravityRAT enumerates files on Windows. [[4]](#4)| + ## MBC Behaviors |Name|Use| |---|---| -|[Anti-Behavioral Analysis::Virtual Machine Detection (B0009)](../anti-behavioral-analysis/virtual-machine-detection.md)|Checks system temperature by recording thermal readings for detecting VMs. Heat levels indicate whether the system is a VM [[1]](#1) | -|[Anti-Behavioral Analysis::Virtual Machine Detection::Unique Hardware/Firmware Check - BIOS (B0009.024)](../anti-behavioral-analysis/virtual-machine-detection.md)|Creates a WMI request to identify the BIOS version. [[1]](#1) | -|[Micro-Objective::Cryptography::Encrypt Data::AES (C0027.001)](../micro-behaviors/cryptography/encrypt-data.md)|GravityRat v3 supports file AES file encryption [[2]](#2) | -|[Anti-Behavioral Analysis::Virtual Machine Detection::Unique Hardware/Firmware Check (B0009.023)](../anti-behavioral-analysis/virtual-machine-detection.md)|Checks if the manufacturer field in the Win32_Computer entry in WMI contains "Virtual", "Vmware", or "Virtualbox" [[2]](#2) | -|[Anti-Behavioral Analysis::Virtual Machine Detection::Modern Specs Check - Processor count (B0009.018)](../anti-behavioral-analysis/virtual-machine-detection.md)|Determines the machine to be a VM if the core count is 1 [[2]](#2) | -|[Anti-Behavioral Analysis::Virtual Machine Detection::Unique Hardware/Firmware Check - MAC Address (B0009.028)](../anti-behavioral-analysis/virtual-machine-detection.md)|Checks if the MAC address starts by a well-known hexadecimal number used by various VM developers [[2]](#2) | -|[Command And Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|Receive data (This capa rule had 1 match) [[4]](#4) | -|[File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|Create directory (This capa rule had 1 match) [[4]](#4) | -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 1 match) [[4]](#4) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 9 matches) [[4]](#4) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Write file on Windows (This capa rule had 7 matches) [[4]](#4) | -|[Process::Suspend Thread (C0055)](../micro-behaviors/process/suspend-thread.md)|Suspend thread (This capa rule had 6 matches) [[4]](#4) | -|[Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Terminate process (This capa rule had 1 match) [[4]](#4) | +|[Anti-Behavioral Analysis::Virtual Machine Detection (B0009)](../anti-behavioral-analysis/virtual-machine-detection.md)|The malware checks the system temperature by recording thermal readings for detecting VMs. Heat levels indicate whether the system is a VM. [[1]](#1)| +|[Anti-Behavioral Analysis::Virtual Machine Detection::Unique Hardware/Firmware Check - BIOS (B0009.024)](../anti-behavioral-analysis/virtual-machine-detection.md)|The malware creates a WMI request to identify the BIOS version. [[1]](#1)| +|[Micro-Objective::Cryptography::Encrypt Data::AES (C0027.001)](../micro-behaviors/cryptography/encrypt-data.md)|GravityRAT v3 supports AES file encryption. [[2]](#2)| +|[Anti-Behavioral Analysis::Virtual Machine Detection::Unique Hardware/Firmware Check (B0009.023)](../anti-behavioral-analysis/virtual-machine-detection.md)|The malware checks if the manufacturer field in the Win32_Computer entry (in WMI) contains "Virtual", "Vmware", or "Virtualbox." [[2]](#2)| +|[Anti-Behavioral Analysis::Virtual Machine Detection::Modern Specs Check - Processor count (B0009.018)](../anti-behavioral-analysis/virtual-machine-detection.md)|GravityRAT determines the machine to be a VM if the core count is 1. [[2]](#2)| +|[Anti-Behavioral Analysis::Virtual Machine Detection::Unique Hardware/Firmware Check - MAC Address (B0009.028)](../anti-behavioral-analysis/virtual-machine-detection.md)|GravityRAT checks if the MAC address starts with a well-known hexadecimal number used by various VM developer. [[2]](#2)| +|[Command And Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|GravityRAT receives data. [[4]](#4)| +|[Micro-Behaviors::File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|GravityRAT creates directories. [[4]](#4)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|GravityRAT deletes files. [[4]](#4)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|GravityRAT reads files on Windows. [[4]](#4)| +|[Micro-Behaviors::File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|GravityRAT writes files on Windows. [[4]](#4)| +|[Micro-Behaviors::Process::Suspend Thread (C0055)](../micro-behaviors/process/suspend-thread.md)|GravityRAT suspends threads. [[4]](#4)| +|[Micro-Behaviors::Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|GravityRAT terminates processes. [[4]](#4)| + ## Indicators of Compromise diff --git a/xample-malware/heriplor.md b/xample-malware/heriplor.md index e617cd4..86315a6 100644 --- a/xample-malware/heriplor.md +++ b/xample-malware/heriplor.md @@ -1,7 +1,7 @@
IDX0032X0016
Aliases
- + @@ -30,7 +30,15 @@ This Trojan is associated with the Energetic Bear group [[1]](#1). |Name|Use| |---|---| -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Access PEB ldr_data (This capa rule had 1 match) [[3]](#3)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Heriplor accesses PEB ldr_data. [[3]](#3)| + + +## MBC Behaviors + +|Name|Use| +|---|---| +|[Anti-Static Analysis::Executable Code Obfuscation::API Hashing (B0032.001)](../anti-static-analysis/executable-code-obfuscation.md)|Malware uses API hashing method. [[1]](#1)| +|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|Malware has the capability to connect with a C2 to download arbitrary code. [[2]](#2)| ## Indicators of Compromise diff --git a/xample-malware/hupigon.md b/xample-malware/hupigon.md index 86e7120..dcc0003 100644 --- a/xample-malware/hupigon.md +++ b/xample-malware/hupigon.md @@ -1,7 +1,7 @@
IDX0026X0017
Aliases
- + @@ -31,84 +31,85 @@ A family of backdoors. |Name|Use| |---|---| -|[Collection::Clipboard Data (T1115)](https://attack.mitre.org/techniques/T1115)|Read clipboard data (This capa rule had 5 matches) [[3]](#3) | -|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Set file attributes (This capa rule had 1 match) [[3]](#3) | -|[Defense Evasion::Hide Artifacts::Hidden Window (T1564.003)](https://attack.mitre.org/techniques/T1564/003)|Hide graphical window (This capa rule had 5 matches) [[3]](#3) | -|[Discovery::Application Window Discovery (T1010)](https://attack.mitre.org/techniques/T1010)|Enumerate gui resources (This capa rule had 2 matches) [[3]](#3) | -|[Discovery::System Location Discovery (T1614)](https://attack.mitre.org/techniques/T1614)|Get geographical location (This capa rule had 5 matches) [[3]](#3) | -|[Discovery::System Location Discovery::System Language Discovery (T1614.001)](https://attack.mitre.org/techniques/T1614/001)|Get keyboard layout (This capa rule had 2 matches) [[3]](#3) | -|[Discovery::System Network Configuration Discovery (T1016)](https://attack.mitre.org/techniques/T1016)|Get local IPv4 addresses (This capa rule had 2 matches) [[3]](#3) | -|[Discovery::System Service Discovery (T1007)](https://attack.mitre.org/techniques/T1007)|Query service status (This capa rule had 3 matches) [[3]](#3) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Link many functions at runtime (This capa rule had 4 matches) [[3]](#3) | -|[Execution::System Services::Service Execution (T1569.002)](https://attack.mitre.org/techniques/T1569/002)|Create service (This capa rule had 2 matches) [[3]](#3) | -|[Impact::Service Stop (T1489)](https://attack.mitre.org/techniques/T1489)|Stop service (This capa rule had 1 match) [[3]](#3) | -|[Impact::System Shutdown/Reboot (T1529)](https://attack.mitre.org/techniques/T1529)|Shutdown system (This capa rule had 1 match) [[3]](#3) | -|[Persistence::Create or Modify System Process::Windows Service (T1543.003)](https://attack.mitre.org/techniques/T1543/003)|Start service (This capa rule had 1 match) [[3]](#3) | -|[Privilege Escalation::Access Token Manipulation (T1134)](https://attack.mitre.org/techniques/T1134)|Acquire debug privileges (This capa rule had 2 matches) [[3]](#3) | +|[Collection::Clipboard Data (T1115)](https://attack.mitre.org/techniques/T1115)|Hupigon reads clipboard data. [[3]](#3)| +|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Hupigon sets file attributes. [[3]](#3)| +|[Defense Evasion::Hide Artifacts::Hidden Window (T1564.003)](https://attack.mitre.org/techniques/T1564/003)|Hupigon hides a graphical window. [[3]](#3)| +|[Discovery::Application Window Discovery (T1010)](https://attack.mitre.org/techniques/T1010)|Hupigon enumerates GUI resources. [[3]](#3)| +|[Discovery::System Location Discovery (T1614)](https://attack.mitre.org/techniques/T1614)|Hupigon gets geographical locations. [[3]](#3)| +|[Discovery::System Location Discovery::System Language Discovery (T1614.001)](https://attack.mitre.org/techniques/T1614/001)|Hupigon gets keyboard layouts. [[3]](#3)| +|[Discovery::System Network Configuration Discovery (T1016)](https://attack.mitre.org/techniques/T1016)|Hupigon gets local IPv4 addresses. [[3]](#3)| +|[Discovery::System Service Discovery (T1007)](https://attack.mitre.org/techniques/T1007)|Hupigon queries service status. [[3]](#3)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Hupigon links many functions at runtime. [[3]](#3)| +|[Execution::System Services::Service Execution (T1569.002)](https://attack.mitre.org/techniques/T1569/002)|Hupigon creates services. [[3]](#3)| +|[Impact::Service Stop (T1489)](https://attack.mitre.org/techniques/T1489)|Hupigon stops services. [[3]](#3)| +|[Impact::System Shutdown/Reboot (T1529)](https://attack.mitre.org/techniques/T1529)|Hupigon shutdowns systems. [[3]](#3)| +|[Persistence::Create or Modify System Process::Windows Service (T1543.003)](https://attack.mitre.org/techniques/T1543/003)|Hupigon starts services. [[3]](#3)| +|[Privilege Escalation::Access Token Manipulation (T1134)](https://attack.mitre.org/techniques/T1134)|Hupigon acquires debug privileges. [[3]](#3)| + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|The malware injects itself into processes such as cmd.exe, notepad.exe [[2]](#2) | -|[Defense Evasion::Rootkit (E1014)](../defense-evasion/rootkit.md)| Certain variants of the malware may have rootkit functionality [[2]](#2) | -|[Collection::Keylogging (F0002)](../collection/keylogging.md)|Certain variants of the malware may have keylogging functionality [[2]](#2) | -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|Hupigon drops the file "Systen.dll" and adds the registry entry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS DllName = "%System%\Systen.dll". [[1]](#1) | -|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|The malware adds many entries to the registry [[1]](#1) | -|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|Log keystrokes via polling (This capa rule had 6 matches) [[3]](#3) | -|[Collection::Screen Capture::WinAPI (E1113.m01)](../collection/screen-capture.md)|Capture screenshot (This capa rule had 2 matches) [[3]](#3) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 8 matches) [[3]](#3) | -|[Defense Evasion::Obfuscated Files or Information::Encryption-Standard Algorithm (E1027.m05)](../defense-evasion/obfuscated-files-or-information.md)|Encrypt data using DES (This capa rule had 1 match) [[3]](#3) | -|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|Get graphical window text (This capa rule had 1 match) [[3]](#3) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Enumerate files recursively (This capa rule had 1 match) [[3]](#3) | -|[Discovery::File and Directory Discovery::Log File (E1083.m01)](../discovery/file-and-directory-discovery.md)|Access the Windows event log (This capa rule had 1 match) [[3]](#3) | -|[Impact::Clipboard Modification (E1510)](../impact/clipboard-modification.md)|Replace clipboard data (This capa rule had 1 match) [[3]](#3) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Query environment variable (This capa rule had 1 match) [[3]](#3) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Accept command line arguments (This capa rule had 2 matches) [[3]](#3) | -|[Persistence::Registry Run Keys / Startup Folder (E1547.001)](../persistence/registry-run-keys-startup-folder.md)|Persist via Run registry key (This capa rule had 1 match) [[3]](#3) | -|[Defense Evasion::Process Injection::Process Hollowing (E1055.012)](../defense-evasion/process-injection.md)|Use process replacement (This capa rule had 1 match) [[3]](#3) | +|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|The malware injects itself into processes, such as cmd.exe and notepad.exe. [[2]](#2)| +|[Defense Evasion::Rootkit (E1014)](../defense-evasion/rootkit.md)|Certain Hupigon variants may have rootkit functionality. [[2]](#2)| +|[Collection::Keylogging (F0002)](../collection/keylogging.md)|Certain Hupigon variants may have keylogging functionality. [[2]](#2)| +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|Hupigon drops the file "Systen.dll" and adds the registry entry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS DllName = "%System%\Systen.dll". [[1]](#1)| +|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|The malware adds entries to the registry. [[1]](#1)| +|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|Hupigon logs keystrokes via polling. [[3]](#3)| +|[Collection::Screen Capture::WinAPI (E1113.m01)](../collection/screen-capture.md)|Hupigon captures screenshots. [[3]](#3)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Hupigon encodes data using XOR. [[3]](#3)| +|[Defense Evasion::Obfuscated Files or Information::Encryption-Standard Algorithm (E1027.m05)](../defense-evasion/obfuscated-files-or-information.md)|Hupigon encrypts data using DES. [[3]](#3)| +|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|Hupigon gets graphical window text. [[3]](#3)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Hupigon enumerates files recursively. [[3]](#3)| +|[Discovery::File and Directory Discovery::Log File (E1083.m01)](../discovery/file-and-directory-discovery.md)|Hupigon accesses Windows event logs. [[3]](#3)| +|[Impact::Clipboard Modification (E1510)](../impact/clipboard-modification.md)|Hupigon replaces clipboard data. [[3]](#3)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Hupigon queries environment variables. [[3]](#3)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Hupigon accepts command line arguments. [[3]](#3)| +|[Persistence::Registry Run Keys / Startup Folder (E1547.001)](../persistence/registry-run-keys-startup-folder.md)|Hupigon persists via Run registry key. [[3]](#3)| +|[Defense Evasion::Process Injection::Process Hollowing (E1055.012)](../defense-evasion/process-injection.md)|Hupigon uses process replacement. [[3]](#3)| ## MBC Behaviors |Name|Use| |---|---| -|[Impact::Remote Access (B0022)](../impact/remote-access.md)|The malware acts as a backdoor [[1]](#1) | -|[Anti-Behavioral Analysis::Conditional Execution::Runs as Service (B0025.007)](../execution/conditional-execution.md)|Run as service (This capa rule had 1 match) [[3]](#3) | -|[Anti-Behavioral Analysis::Debugger Detection::Anti-debugging Instructions (B0001.034)](../anti-behavioral-analysis/debugger-detection.md)|Execute anti-debugging instructions (This capa rule had 1 match) [[3]](#3) | -|[Anti-Behavioral Analysis::Debugger Detection::Software Breakpoints (B0001.025)](../anti-behavioral-analysis/debugger-detection.md)|Check for software breakpoints (This capa rule had 2 matches) [[3]](#3) | -|[Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)](../anti-behavioral-analysis/debugger-detection.md)|Check for time delay via GetTickCount (This capa rule had 6 matches) [[3]](#3) | -|[Anti-Static Analysis::Disassembler Evasion::Argument Obfuscation (B0012.001)](../anti-static-analysis/disassembler-evasion.md)|Contain obfuscated stackstrings (This capa rule had 1 match) [[3]](#3) | -|[Command And Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|Receive data (This capa rule had 2 matches) [[3]](#3) | -|[Command And Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|Send data (This capa rule had 2 matches) [[3]](#3) | -|[Communication::DNS Communication::Resolve (C0011.001)](../micro-behaviors/communication/dns-communication.md)|Resolve DNS (This capa rule had 1 match) [[3]](#3) | -|[Communication::Interprocess Communication::Create Pipe (C0003.001)](../micro-behaviors/communication/interprocess-communication.md)|Create two anonymous pipes (This capa rule had 1 match) [[3]](#3) | -|[Communication::Interprocess Communication::Write Pipe (C0003.004)](../micro-behaviors/communication/interprocess-communication.md)|Write pipe (This capa rule had 1 match) [[3]](#3) | -|[Communication::Socket Communication::Create UDP Socket (C0001.010)](../micro-behaviors/communication/socket-communication.md)|Create UDP socket (This capa rule had 1 match) [[3]](#3) | -|[Cryptography::Encrypt Data::3DES (C0027.004)](../micro-behaviors/cryptography/encrypt-data.md)|Encrypt data using DES (This capa rule had 1 match) [[3]](#3) | -|[Data::Compression Library (C0060)](../micro-behaviors/data/compression-library.md)|Linked against ZLIB (This capa rule had 1 match) [[3]](#3) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 8 matches) [[3]](#3) | -|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Enumerate PE sections (This capa rule had 3 matches) [[3]](#3) | -|[File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|Copy file (This capa rule had 1 match) [[3]](#3) | -|[File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|Create directory (This capa rule had 1 match) [[3]](#3) | -|[File System::Delete Directory (C0048)](../micro-behaviors/file-system/delete-directory.md)|Delete directory (This capa rule had 1 match) [[3]](#3) | -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 1 match) [[3]](#3) | -|[File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|Get file attributes (This capa rule had 3 matches) [[3]](#3) | -|[File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|Move file (This capa rule had 1 match) [[3]](#3) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 1 match) [[3]](#3) | -|[File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|Set file attributes (This capa rule had 1 match) [[3]](#3) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Write file on Windows (This capa rule had 4 matches) [[3]](#3) | -|[Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Allocate RWX memory (This capa rule had 4 matches) [[3]](#3) | -|[Operating System::Registry::Delete Registry Key (C0036.002)](../micro-behaviors/operating-system/registry.md)|Delete registry key (This capa rule had 1 match) [[3]](#3) | -|[Operating System::Registry::Delete Registry Value (C0036.007)](../micro-behaviors/operating-system/registry.md)|Delete registry value (This capa rule had 3 matches) [[3]](#3) | -|[Operating System::Registry::Query Registry Key (C0036.005)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry key (This capa rule had 4 matches) [[3]](#3) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 8 matches) [[3]](#3) | -|[Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Set registry value (This capa rule had 2 matches) [[3]](#3) | -|[Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Create mutex (This capa rule had 1 match) [[3]](#3) | -|[Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Create process on Windows (This capa rule had 9 matches) [[3]](#3) | -|[Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|Create thread (This capa rule had 6 matches) [[3]](#3) | -|[Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|Set thread local storage value (This capa rule had 1 match) [[3]](#3) | -|[Process::Suspend Thread (C0055)](../micro-behaviors/process/suspend-thread.md)|Suspend thread (This capa rule had 1 match) [[3]](#3) | -|[Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Terminate process (This capa rule had 3 matches) [[3]](#3) | +|[Impact::Remote Access (B0022)](../impact/remote-access.md)|The malware acts as a backdoor. [[1]](#1)| +|[Anti-Behavioral Analysis::Conditional Execution::Runs as Service (B0025.007)](../execution/conditional-execution.md)|Hupigon runs as a service. [[3]](#3)| +|[Anti-Behavioral Analysis::Debugger Detection::Anti-debugging Instructions (B0001.034)](../anti-behavioral-analysis/debugger-detection.md)|Hupigon executes anti-debugging instructions. [[3]](#3)| +|[Anti-Behavioral Analysis::Debugger Detection::Software Breakpoints (B0001.025)](../anti-behavioral-analysis/debugger-detection.md)|Hupigon checks for software breakpoints. [[3]](#3)| +|[Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)](../anti-behavioral-analysis/debugger-detection.md)|Hupigon checks for a time delay via GetTickCount. [[3]](#3)| +|[Anti-Static Analysis::Disassembler Evasion::Argument Obfuscation (B0012.001)](../anti-static-analysis/disassembler-evasion.md)|Hupigon contains obfuscated stack strings. [[3]](#3)| +|[Micro-Behaviors::Command And Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|Hupigon receives data. [[3]](#3)| +|[Micro-Behaviors::Command And Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|Hupigon sends data. [[3]](#3)| +|[Micro-Behaviors::Communication::DNS Communication::Resolve (C0011.001)](../micro-behaviors/communication/dns-communication.md)|Hupigon resolves DNS. [[3]](#3)| +|[Micro-Behaviors::Communication::Interprocess Communication::Create Pipe (C0003.001)](../micro-behaviors/communication/interprocess-communication.md)|Hupigon creates two anonymous pipes. [[3]](#3)| +|[Micro-Behaviors::Communication::Interprocess Communication::Write Pipe (C0003.004)](../micro-behaviors/communication/interprocess-communication.md)|Hupigon writes pipes. [[3]](#3)| +|[Micro-Behaviors::Communication::Socket Communication::Create UDP Socket (C0001.010)](../micro-behaviors/communication/socket-communication.md)|Hupigon creates UDP sockets. [[3]](#3)| +|[Micro-Behaviors::Cryptography::Encrypt Data::3DES (C0027.004)](../micro-behaviors/cryptography/encrypt-data.md)|Hupigon encrypts data using DES. [[3]](#3)| +|[Micro-Behaviors::Data::Compression Library (C0060)](../micro-behaviors/data/compression-library.md)|Hupigon linked against ZLIB. [[3]](#3)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Hupigon encodes data using XOR. [[3]](#3)| +|[Micro-Behaviors::Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Hupigon enumerates PE sections. [[3]](#3)| +|[Micro-Behaviors::File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|Hupigon copies files. [[3]](#3)| +|[Micro-Behaviors::File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|Hupigon creates directories. [[3]](#3)| +|[Micro-Behaviors::File System::Delete Directory (C0048)](../micro-behaviors/file-system/delete-directory.md)|Hupigon deletes directories. [[3]](#3)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Hupigon deletes files. [[3]](#3)| +|[Micro-Behaviors::File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|Hupigon gets file attributes. [[3]](#3)| +|[Micro-Behaviors::File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|Hupigon moves files. [[3]](#3)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Hupigon reads files on Windows. [[3]](#3)| +|[Micro-Behaviors::File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|Hupigon sets file attributes. [[3]](#3)| +|[Micro-Behaviors::File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Hupigon writes files on Windows. [[3]](#3)| +|[Micro-Behaviors::Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Hupigon allocates RWX memory. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Delete Registry Key (C0036.002)](../micro-behaviors/operating-system/registry.md)|Hupigon deletes registry keys. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Delete Registry Value (C0036.007)](../micro-behaviors/operating-system/registry.md)|Hupigon deletes registry values. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Key (C0036.005)](../micro-behaviors/operating-system/registry.md)|Hupigon queries or enumerates registry keys. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Hupigon queries or enumerates registry values. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Hupigon sets registry values. [[3]](#3)| +|[Micro-Behaviors::Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Hupigon creates mutexes. [[3]](#3)| +|[Micro-Behaviors::Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Hupigon creates processes on Windows. [[3]](#3)| +|[Micro-Behaviors::Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|Hupigon creates threads. [[3]](#3)| +|[Micro-Behaviors::Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|Hupigon sets thread local storage values. [[3]](#3)| +|[Micro-Behaviors::Process::Suspend Thread (C0055)](../micro-behaviors/process/suspend-thread.md)|Hupigon suspends threads. [[3]](#3)| +|[Micro-Behaviors::Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Hupigon terminates processes. [[3]](#3)| ## Indicators of Compromise diff --git a/xample-malware/kovter.md b/xample-malware/kovter.md index 04f51c9..01a3074 100644 --- a/xample-malware/kovter.md +++ b/xample-malware/kovter.md @@ -1,7 +1,7 @@
IDX0008X0018
Aliases
- + @@ -31,59 +31,60 @@ A trojan that performs click-fraud. |Name|Use| |---|---| -|[Initial Access::Phishing::Spearphishing Attachment (T1566.001)](https://attack.mitre.org/techniques/T1566/001/)|The malware is sent out to victims via an attachment [[2]](#2) | -|[Execution::User Execution::Malicious File (T1204.002)](https://attack.mitre.org/techniques/T1204/002/)|The malware relies on a victim to execute itself [[2]](#2) | -|[Defense Evasion::System Binary Proxy Execution::Mshta (T1218.005)](https://attack.mitre.org/techniques/T1218/005/)|The malware uses mshta.exe to run Javascript [[1]](#1) | -|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Set file attributes (This capa rule had 3 matches) [[3]](#3) | -|[Discovery::Application Window Discovery (T1010)](https://attack.mitre.org/techniques/T1010)|Find graphical window (This capa rule had 11 matches) [[3]](#3) | -|[Discovery::System Location Discovery (T1614)](https://attack.mitre.org/techniques/T1614)|Get geographical location (This capa rule had 1 match) [[3]](#3) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Get ntdll base address (This capa rule had 2 matches) [[3]](#3) | -|[Execution::System Services::Service Execution (T1569.002)](https://attack.mitre.org/techniques/T1569/002)|Interact with driver via control codes (This capa rule had 3 matches) [[3]](#3) | +|[Initial Access::Phishing::Spearphishing Attachment (T1566.001)](https://attack.mitre.org/techniques/T1566/001/)|The malware is sent out to victims via an attachment. [[2]](#2)| +|[Execution::User Execution::Malicious File (T1204.002)](https://attack.mitre.org/techniques/T1204/002/)|The malware relies on a victim to execute itself. [[2]](#2)| +|[Defense Evasion::System Binary Proxy Execution::Mshta (T1218.005)](https://attack.mitre.org/techniques/T1218/005/)|The malware uses mshta.exe to run Javascript. [[1]](#1)| +|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Kovter sets file attributes. [[3]](#3)| +|[Discovery::Application Window Discovery (T1010)](https://attack.mitre.org/techniques/T1010)|Kovter finds graphical windows. [[3]](#3)| +|[Discovery::System Location Discovery (T1614)](https://attack.mitre.org/techniques/T1614)|Kovter gets geographical locations. [[3]](#3)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Kovter gets ntdll base address. [[3]](#3)| +|[Execution::System Services::Service Execution (T1569.002)](https://attack.mitre.org/techniques/T1569/002)|Kovter interacts with drivers via control codes. [[3]](#3)| ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Impact::Generate Traffic from Victim (E1643)](../impact/generate-traffic-from-victim.md)|Performs click-fraud. [[1]](#1) | -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|The malware writes an autorun registry entry [[2]](#2) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|The malware executes malicious javascript and powershell [[1]](#1) | -|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|The malware modifies the registry during execution [[2]](#2) | -|[Defense Evasion::Obfuscated Files or Information (E1027)](../defense-evasion/obfuscated-files-or-information.md)|The malware will use a key to decrypt text from a URL to create more malicious code [[1]](#1) | -|[Anti-Static Analysis::Software Packing (F0001)](../anti-static-analysis/software-packing.md)|The malware comes packed by a crypter/FUD [[1]](#1) | -|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|Log keystrokes via polling (This capa rule had 1 match) [[3]](#3) | -|[Collection::Screen Capture::WinAPI (E1113.m01)](../collection/screen-capture.md)|Capture screenshot (This capa rule had 1 match) [[3]](#3) | -|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|Get graphical window text (This capa rule had 2 matches) [[3]](#3) | -|[Discovery::File and Directory Discovery::Log File (E1083.m01)](../discovery/file-and-directory-discovery.md)|Access the Windows event log (This capa rule had 2 matches) [[3]](#3) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Get file version info (This capa rule had 3 matches) [[3]](#3) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Get disk information (This capa rule had 1 match) [[3]](#3) | +|[Impact::Generate Traffic from Victim (E1643)](../impact/generate-traffic-from-victim.md)|Kovter performs click-fraud. [[1]](#1)| +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|The malware writes an autorun registry entry. [[2]](#2)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|The malware executes malicious javascript and powershell. [[1]](#1)| +|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|The malware modifies the registry during execution. [[2]](#2)| +|[Defense Evasion::Obfuscated Files or Information (E1027)](../defense-evasion/obfuscated-files-or-information.md)|The malware will use a key to decrypt text from a URL to create additional malicious code. [[1]](#1)| +|[Anti-Static Analysis::Software Packing (F0001)](../anti-static-analysis/software-packing.md)|The malware comes packed by a crypter/FUD. [[1]](#1)| +|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|Kovter logs keystrokes via polling. [[3]](#3)| +|[Collection::Screen Capture::WinAPI (E1113.m01)](../collection/screen-capture.md)|Kovter captures screenshots. [[3]](#3)| +|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|Kovter gets graphical window text. [[3]](#3)| +|[Discovery::File and Directory Discovery::Log File (E1083.m01)](../discovery/file-and-directory-discovery.md)|Kovter accesses Windows event logs. [[3]](#3)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Kovter gets file version info. [[3]](#3)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Kovter gets disk information. [[3]](#3)| + ## MBC Behaviors |Name|Use| |---|---| -|[Defense Evasion::Alternative Installation Location::Registry Install (B0027.002)](../defense-evasion/alternative-installation-location.md)|Stores malware files in the Registry instead of the hard drive [[2]](#2) | -|[Command And Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|Receive data (This capa rule had 16 matches) [[3]](#3) | -|[Command And Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|Send data (This capa rule had 1 match) [[3]](#3) | -|[Communication::HTTP Communication::Connect to Server (C0002.009)](../micro-behaviors/communication/http-communication.md)|Connect to HTTP server (This capa rule had 2 matches) [[3]](#3) | -|[Communication::HTTP Communication::Create Request (C0002.012)](../micro-behaviors/communication/http-communication.md)|Create HTTP request (This capa rule had 4 matches) [[3]](#3) | -|[Cryptography::Cryptographic Hash (C0029)](../micro-behaviors/cryptography/cryptographic-hash.md)|Hash data via WinCrypt (This capa rule had 22 matches) [[3]](#3) | -|[Cryptography::Decrypt Data (C0031)](../micro-behaviors/cryptography/decrypt-data.md)|Encrypt or decrypt via WinCrypt (This capa rule had 1 match) [[3]](#3) | -|[Cryptography::Encryption Key (C0028)](../micro-behaviors/cryptography/encryption-key.md)|Create new key via CryptAcquireContext (This capa rule had 1 match) [[3]](#3) | -|[File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|Copy file (This capa rule had 5 matches) [[3]](#3) | -|[File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|Create directory (This capa rule had 14 matches) [[3]](#3) | -|[File System::Delete Directory (C0048)](../micro-behaviors/file-system/delete-directory.md)|Delete directory (This capa rule had 4 matches) [[3]](#3) | -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 2 matches) [[3]](#3) | -|[File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|Move file (This capa rule had 24 matches) [[3]](#3) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 4 matches) [[3]](#3) | -|[File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|Set file attributes (This capa rule had 3 matches) [[3]](#3) | -|[Operating System::Environment Variable::Set Variable (C0034.001)](../micro-behaviors/operating-system/environment-variable.md)|Set environment variable (This capa rule had 3 matches) [[3]](#3) | -|[Operating System::Registry::Create Registry Key (C0036.004)](../micro-behaviors/operating-system/registry.md)|Create or open registry key (This capa rule had 14 matches) [[3]](#3) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 2 matches) [[3]](#3) | -|[Process::Allocate Thread Local Storage (C0040)](../micro-behaviors/process/allocate-thread-local-storage.md)|Allocate thread local storage (This capa rule had 3 matches) [[3]](#3) | -|[Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Create mutex (This capa rule had 2 matches) [[3]](#3) | -|[Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Create process on Windows (This capa rule had 22 matches) [[3]](#3) | -|[Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|Set thread local storage value (This capa rule had 3 matches) [[3]](#3) | -|[Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Terminate process (This capa rule had 6 matches) [[3]](#3) | +|[Defense Evasion::Alternative Installation Location::Registry Install (B0027.002)](../defense-evasion/alternative-installation-location.md)|Kovter stores malware files in the Registry instead of on the hard drive. [[2]](#2)| +|[Command And Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|Kovter sends data. [[3]](#3)| +|[Command And Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|Kovter receives data. [[3]](#3)| +|[Micro-Behaviors::Communication::HTTP Communication::Connect to Server (C0002.009)](../micro-behaviors/communication/http-communication.md)|Kovter connects to a HTTP server. [[3]](#3)| +|[Micro-Behaviors::Communication::HTTP Communication::Create Request (C0002.012)](../micro-behaviors/communication/http-communication.md)|Kovter creates HTTP requests. [[3]](#3)| +|[Micro-Behaviors::Cryptography::Cryptographic Hash (C0029)](../micro-behaviors/cryptography/cryptographic-hash.md)|Kovter hashes data via WinCrypt. [[3]](#3)| +|[Micro-Behaviors::Cryptography::Decrypt Data (C0031)](../micro-behaviors/cryptography/decrypt-data.md)|Kovter encrypts or decrypts via WinCrypt. [[3]](#3)| +|[Micro-Behaviors::Cryptography::Encryption Key (C0028)](../micro-behaviors/cryptography/encryption-key.md)|Kovter creates new keys via CryptAcquireContext. [[3]](#3)| +|[Micro-Behaviors::File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|Kovter copies files. [[3]](#3)| +|[Micro-Behaviors::File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|Kovter creates directories. [[3]](#3)| +|[Micro-Behaviors::File System::Delete Directory (C0048)](../micro-behaviors/file-system/delete-directory.md)|Kovter deletes directories. [[3]](#3)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Kovter deletes files. [[3]](#3)| +|[Micro-Behaviors::File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|Kovter moves files. [[3]](#3)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Kovter reads files on Windows. [[3]](#3)| +|[Micro-Behaviors::File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|Kovter sets file attributes. [[3]](#3)| +|[Micro-Behaviors::Operating System::Environment Variable::Set Variable (C0034.001)](../micro-behaviors/operating-system/environment-variable.md)|Kovter sets environment variables. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Create Registry Key (C0036.004)](../micro-behaviors/operating-system/registry.md)|Kovter creates or opens registry keys. [[3]](#3)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Kovter queries or enumerates registry values. [[3]](#3)| +|[Micro-Behaviors::Process::Allocate Thread Local Storage (C0040)](../micro-behaviors/process/allocate-thread-local-storage.md)|Kovter allocates thread local storage. [[3]](#3)| +|[Micro-Behaviors::Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Kovter creates mutexes. [[3]](#3)| +|[Micro-Behaviors::Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Kovter creates processes on Windows. [[3]](#3)| +|[Micro-Behaviors::Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|Kovter sets thread local storage values. [[3]](#3)| +|[Micro-Behaviors::Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Kovter terminates processes. [[3]](#3)| ## Indicators of Compromise diff --git a/xample-malware/kraken.md b/xample-malware/kraken.md index 20590f6..8cb697f 100644 --- a/xample-malware/kraken.md +++ b/xample-malware/kraken.md @@ -1,7 +1,7 @@
IDX0009X0019
Aliases
- + @@ -30,24 +30,27 @@ A family of bots. |Name|Use| |---|---| -|[Command and Control::Dynamic Resolution::Domain Generation Algorithms (T1568.002)](https://attack.mitre.org/techniques/T1568/002/)|Uses a domain name generator.  [[1]](#1) | -|[Command and Control::Application Layer Protocol::Web Protocols (T1071.001)](https://attack.mitre.org/techniques/T1071/001/)|The malware uses HTTP to communicate with C2 [[1]](#1) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Access PEB ldr_data (This capa rule had 1 match) [[2]](#2) | +|[Command and Control::Dynamic Resolution::Domain Generation Algorithms (T1568.002)](https://attack.mitre.org/techniques/T1568/002/)|Kraken uses a domain name generator to provide new domains. [[1]](#1)| +|[Command and Control::Application Layer Protocol::Web Protocols (T1071.001)](https://attack.mitre.org/techniques/T1071/001/)|The malware uses HTTP to communicate with C2. [[1]](#1)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Kraken accesses PEB ldr_data. [[2]](#2)| + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 2 matches) [[2]](#2) | +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Kraken encodes data using XOR. [[2]](#2)| + ## MBC Behaviors |Name|Use| |---|---| -|[Command and Control::Domain Name Generation (B0003)](../command-and-control/domain-name-generation.md)| Uses a domain name generator. [[1]](#1) | -|[Anti-Behavioral Analysis::Memory Dump Evasion (B0006)](../anti-behavioral-analysis/memory-dump-evasion.md)|Dumping Kraken's c.dll module from the heap of its own process is tricky because its PE-header is wiped out. [[1]](#1) | -|[Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Encrypt data using RC4 PRGA (This capa rule had 2 matches) [[2]](#2) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 2 matches) [[2]](#2) | +|[Command and Control::Domain Name Generation (B0003)](../command-and-control/domain-name-generation.md)| Kraken uses a domain name generator to provide new domains. [[1]](#1)| +|[Anti-Behavioral Analysis::Memory Dump Evasion (B0006)](../anti-behavioral-analysis/memory-dump-evasion.md)|Dumping Kraken's c.dll module from the heap of its own process is tricky because its PE-header is erased in memory. [[1]](#1)| +|[Micro-Behaviors::Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Kraken encrypts data using RC4 PRGA. [[2]](#2)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Kraken encodes data using XOR. [[2]](#2)| + ## Indicators of Compromise diff --git a/xample-malware/locky-bart.md b/xample-malware/locky-bart.md index fc78cae..7c9af5b 100644 --- a/xample-malware/locky-bart.md +++ b/xample-malware/locky-bart.md @@ -1,7 +1,7 @@
IDX0010X0020
Aliases
- + @@ -26,45 +26,49 @@ Locky Bart is ransomware. [[1]](#1) + ## ATT&CK Techniques |Name|Use| |---|---| -|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057/)|Gathers information from the victim's machine to create an encryption key. [[1]](#1) | -|[Discovery::System Time Discovery (T1057)](https://attack.mitre.org/techniques/T1124/)|Gathers information from the victim's machine to create an encryption key. [[1]](#1) | -|[Discovery::System Location Discovery::System Language Discovery (T1614.001)](https://attack.mitre.org/techniques/T1614/001)|Identify system language via API (This capa rule had 1 match) [[2]](#2) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Parse PE header (This capa rule had 2 matches) [[2]](#2) | +|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057/)|Locky Bart gathers information from the victim's machine to create an encryption key. [[1]](#1)| +|[Discovery::System Location Discovery::System Language Discovery (T1614.001)](https://attack.mitre.org/techniques/T1614/001)|Locky Bart identifies the system language via API. [[2]](#2)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Locky Bart parses PE headers. [[2]](#2)| + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Impact::Data Encrypted for Impact (E1486)](../impact/data-encrypted-for-impact.md)|Encrypts files for ransom without any connection to the Internet [[1]](#1) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 4 matches) [[2]](#2) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Get file size (This capa rule had 1 match) [[2]](#2) | +|[Impact::Data Encrypted for Impact (E1486)](../impact/data-encrypted-for-impact.md)|Locky Bart encrypts files for ransom without any connection to the Internet. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Locky Bart encodes data using XOR. [[2]](#2)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Locky Bart gets a file size. [[2]](#2)| + ## MBC Behaviors |Name|Use| |---|---| -|[Anti-Static Analysis::Executable Code Virtualization (B0008)](../anti-static-analysis/executable-code-virtualization.md)|Code virtualization is added to the Locky Bart binary using WPProtect. [[1]](#1) | -|[Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Encrypt data using RC4 PRGA (This capa rule had 1 match) [[2]](#2) | -|[Cryptography::Encryption Key (C0028)](../micro-behaviors/cryptography/encryption-key.md)|Create new key via CryptAcquireContext (This capa rule had 1 match) [[2]](#2) | -|[Cryptography::Generate Pseudo-random Sequence::Use API (C0021.003)](../micro-behaviors/cryptography/generate-pseudorandom-sequence.md)|Generate random numbers via WinAPI (This capa rule had 1 match) [[2]](#2) | -|[Data::Check String (C0019)](../micro-behaviors/data/check-string.md)|Reference Base64 string (This capa rule had 1 match) [[2]](#2) | -|[Data::Checksum::CRC32 (C0032.001)](../micro-behaviors/data/checksum.md)|Hash data with CRC32 (This capa rule had 2 matches) [[2]](#2) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 4 matches) [[2]](#2) | -|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Enumerate PE sections (This capa rule had 2 matches) [[2]](#2) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 2 matches) [[2]](#2) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Write file on Windows (This capa rule had 3 matches) [[2]](#2) | -|[Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Set registry value (This capa rule had 1 match) [[2]](#2) | -|[Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|Create thread (This capa rule had 1 match) [[2]](#2) | +|[Anti-Static Analysis::Executable Code Virtualization (B0008)](../anti-static-analysis/executable-code-virtualization.md)|Code virtualization is added to the Locky Bart binary using WPProtect. [[1]](#1)| +|[Micro-Behaviors::Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Locky Bart encrypts data using RC4 PRGA. [[2]](#2)| +|[Micro-Behaviors::Cryptography::Encryption Key (C0028)](../micro-behaviors/cryptography/encryption-key.md)|Locky Bart creates a new key via CryptAcquireContext. [[2]](#2)| +|[Micro-Behaviors::Cryptography::Generate Pseudo-random Sequence::Use API (C0021.003)](../micro-behaviors/cryptography/generate-pseudorandom-sequence.md)|Locky Bart generates random numbers via WinAPI. [[2]](#2)| +|[Micro-Behaviors::Data::Check String (C0019)](../micro-behaviors/data/check-string.md)|Locky Bart references Base64 strings. [[2]](#2)| +|[Micro-Behaviors::Data::Checksum::CRC32 (C0032.001)](../micro-behaviors/data/checksum.md)|Locky Bart hashes data with CRC32. [[2]](#2)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Locky Bart encodes data using XOR. [[2]](#2)| +|[Micro-Behaviors::Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Locky Bart enumerates PE sections. [[2]](#2)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Locky Bart reads files on Windows. [[2]](#2)| +|[Micro-Behaviors::File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Locky Bart writes files on Windows. [[2]](#2)| +|[Micro-Behaviors::Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Locky Bart sets registry values. [[2]](#2)| +|[Micro-Behaviors::Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|Locky Bart creates threads. [[2]](#2)| + ## Indicators of Compromise SHA256 Hashes - c285e376201e2941154ec1a9acd8658cd5e0ea975c694a3fe3e9a9897efc2680 + ## References [1] https://blog.malwarebytes.com/threat-analysis/2017/01/locky-bart-ransomware-and-backend-server-analysis/ diff --git a/xample-malware/matanbuchus.md b/xample-malware/matanbuchus.md new file mode 100644 index 0000000..f966096 --- /dev/null +++ b/xample-malware/matanbuchus.md @@ -0,0 +1,81 @@ + +
IDX0011X0021
Aliases
+ + + + + + + + + + + + + + + + +
IDX0022
AliasesNone
PlatformsWindows
Year2021
+ + +# Matanbuchus + +A commercial loader that consists of 2 stages used to download and execute payloads. + + +## ATT&CK Techniques + +|Name|Use| +|---|---| +|[Privilege Escalation::Process Injection::Dynamic-Link Library Injection (T1055.001)](https://attack.mitre.org/techniques/T1055/001/)|Malware loads every part of the malware from different DLLs. [[1]](#1) [[2]](#2)| +|[Defense Evasion::System Binary Proxy Execution::Regsvr32 (T1218.010)](https://attack.mitre.org/techniques/T1218/010/)|Malware downloads a DLL from a remote server and launches it through regsvr32. In some cases, the loader saves the payload as an .ocx extension. [[1]](#1) [[2]](#2)| +|[Discovery::File and Directory Discovery (T1083)](https://attack.mitre.org/techniques/T1083/)|Malware queries target computer for a target folder. [[1]](#1)| +|[Execution::Scheduled Task/Job::Scheduled Task (T1053.005)](https://attack.mitre.org/techniques/T1053/005/)|Malware schedules a task to execute regsvr32.exe every 3 minutes. [[1]](#1)| +|[Discovery::System Location Discovery::System Language Discovery (T1614.001)](https://attack.mitre.org/techniques/T1614/001/)|Malware checks the language ID for the victim computer's language. If the language is part of the Commonwealth of Independent States (CIS), then the malware terminates. [[2]](#2)| +|[Discovery::Query Registry (T1012)](https://attack.mitre.org/techniques/T1012/)|Malware loader retrieves the network domain name and computer name. [[2]](#2)| +|[Discovery::System Information Discovery (T1082)](https://attack.mitre.org/techniques/T1082/)|Malware loader collects the full path of the process running the loader, basic CPU information, machine architecture, number of processors, victim logon server's name, RAM size, DNS domain, and MAC address. [[2]](#2)| +|[Persistence::Create or Modify System Process::Windows Service (T1543.003)](https://attack.mitre.org/techniques/T1543/003/)|Malware loader creates a new instance of explorer.exe. [[2]](#2)| +|[Execution::Command and Scripting Interpreter::Windows Command Shell (T1059.003)](https://attack.mitre.org/techniques/T1059/003/)|Malware loader runs cmd.exe to start payload with admin privileges. The loader can also act like a bot. [[2]](#2)| +|[Defense Evasion::System Binary Proxy Execution::Rundll32 (T1218.011)](https://attack.mitre.org/techniques/T1218/011/)|Malware loader executes DLLs by using rundll32.exe. [[2]](#2)| +|[Execution::Command and Scripting Interpreter::PowerShell (T1059.001)](https://attack.mitre.org/techniques/T1059/001/)|Malware loader can run PowerShell commands. [[2]](#2)| + + +## Enhanced ATT&CK Techniques + +|Name|Use| +|---|---| +|[Defense Evasion::Hidden Files and Directories::Location (F0005.002)](../defense-evasion/hidden-files-and-directories.md)|The malware searches for a target folder on the victim. If the target folder doesn't exist, the malware creates the folder by calling CreateDirectoryA and downloads the remote file into the new folder. [[1]](#1)| +|[Defense Evasion::Hidden Files and Directories::Extension (F0005.001)](../defense-evasion/hidden-files-and-directories.md)|The malware appends the filename and the extension .ocx to the ProgramData folder path. [[1]](#1)| +|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|The malware downloads DLLs from a hardcoded URL/remote server. [[1]](#1)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|The malware verifies that the working folder from the first stage loader exists on the system. The malware checks for the path for the Opera web browser; if it exists, the malware exits. [[1]](#1) [[2]](#2)| +|[Exfiltration::Archive Collected Data::Encoding-Standard Encoding (E1560.m03)](../exfiltration/archive-collected-data.md)|The malware sends data as a Base64 string of JSON. [[2]](#2)| + + +## MBC Behaviors + +|Name|Use| +|---|---| +|[Anti-Behavioral Analysis::Virtual Machine Detection::Check Processes (B0009.003)](../anti-behavioral-analysis/virtual-machine-detection.md)|Malware checks if it is running in a sandbox. If it is running in a sandbox, the malware exits. [[1]](#1)| +|[Micro-Behaviors::Process::Check Mutex (C0043)](../micro-behaviors/process/check-mutex.md)|Malware checks if multiple instances of the same mutex is running. If multiple instances are running, the malware exits. [[1]](#1)| +|[Anti-Behavioral Analysis::Capture Evasion::Multiple Stages of Loaders (B0036.003)](../anti-behavioral-analysis/capture-evasion.md)|Malware consists of 2 loaders. [[2]](#2)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Malware drops the first loader which is responsible for loading the main loader into memory. [[1]](#1)| +|[Anti-Static Analysis::Executable Code Obfuscation::API Hashing (B0032.001)](../anti-static-analysis/executable-code-obfuscation.md)|The function to import APIs uses a hash value and the DLL name of the target API. The API address returned from the function is stored into a global variance. API calls are obfuscated in the same manner as the stack strings and are resolved dynamically as the malware needs to use them. The malware encodes data in a stack string and copies that data into a global character buffer as a form of string obfuscation. [[1]](#1) [[2]](#2)| +|[Anti-Static Analysis::Executable Code Obfuscation::Stack Strings (B0032.017)](../anti-static-analysis/executable-code-obfuscation.md)|The malware encodes data in a stack string and copies that data into a global character buffer as a form of string obfuscation. Different techniques are used to encrypt and obfuscate strings. Strings are dynamically decrypted when the malware needs to use them. [[1]](#1) [[2]](#2)| +|[Anti-Static Analysis::Executable Code Obfuscation::Entry Point Obfuscation (B0032.009)](../anti-static-analysis/executable-code-obfuscation.md)|The malware has 4 different export functions. [[1]](#1)| +|[Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)](../anti-behavioral-analysis/debugger-detection.md)|The malware calls GetTickCount64 to retrieve timestamp. The malware executes Sleep and Beep in a repeated loop for 10 times. [[1]](#1)| +|[Anti-Behavioral Analysis::Capture Evasion::Memory-Only Payload (B0036.001)](../anti-behavioral-analysis/capture-evasion.md)|Malware downloads multiple payloads (as files and DLLs) that are stored in a memory buffer. [[1]](#1) [[2]](#2)| +|[Micro-Behaviors::Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Malware loader decrypts inner configurations (C2 server address, C2 server's gate, and a string for the RC4 encryption key for communication between the malware and the C2 server) stored in the binary. The malware also encrypts the value of each JSON key with RC4 and encodes the value with Base64. [[2]](#2)| +|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|Malware sends collected data about the system to C2 server. [[2]](#2)| +|[Execution::Remote Commands::Sleep (B0011.005)](../execution/remote-commands.md)|If malware fails to send its collected data, then it sleeps. If the malware fails to execute any command, it sleeps for 4 minutes. [[2]](#2)| +|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|C2 server returns Base64 encoded data containing the information about the next command for the loader. [[2]](#2)| +|[Command and Control::C2 Communication::Execute File (B0030.013)](../command-and-control/c2-communication.md)|The payload is run by explorer.exe, potentially with parameters. [[2]](#2)| +|[Execution::Remote Commands::Uninstall (B0011.006)](../execution/remote-commands.md)|Malware loader can uninstall itself from the victim computer. [[2]](#2)| + + +## References + +[1] https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/ + +[2] https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader + diff --git a/xample-malware/mazarbot.md b/xample-malware/mazarbot.md index f57aea2..401398c 100644 --- a/xample-malware/mazarbot.md +++ b/xample-malware/mazarbot.md @@ -2,7 +2,7 @@ - + @@ -25,26 +25,28 @@ # MazarBot -Targets Android phones via a poisoned text message. +MazarBot targets Android phones via a poisoned text message. + ## ATT&CK Techniques See ATT&CK: [MazarBOT - Techniques Used](https://attack.mitre.org/software/S0303/). + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Impact::Data Destruction (E1485)](../impact/data-destruction.md)|Can erase phone data [[3]](#3)| +|[Impact::Data Destruction (E1485)](../impact/data-destruction.md)|MazarBot can erase phone data. [[3]](#3)| ## MBC Behaviors |Name|Use| |---|---| -|[Impact::Manipulate Network Traffic (B0019)](../impact/manipulate-network-traffic.md)|Intercepts data coming into and going out of device [[1]](#1)| -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Installs a backdoor [[1]](#1)| -|[Execution::Send Poisoned Text Message (B0021)](../execution/send-poisoned-text-message.md)|Can send SMS messages [[2]](#2)| +|[Impact::Manipulate Network Traffic (B0019)](../impact/manipulate-network-traffic.md)|MazarBot intercepts data coming into and going out of the device. [[1]](#1)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|MazarBot installs a backdoor. [[1]](#1)| +|[Execution::Send Poisoned Text Message (B0021)](../execution/send-poisoned-text-message.md)|MazarBot is delivered via a poisoned SMS message. [[2]](#2)| ## Indicators of Compromise diff --git a/xample-malware/mebromi.md b/xample-malware/mebromi.md index 035c53b..f6555b4 100644 --- a/xample-malware/mebromi.md +++ b/xample-malware/mebromi.md @@ -1,7 +1,7 @@
IDX0012X0023
Aliases
- + @@ -28,42 +28,41 @@ A BIOS bootkit. ## ATT&CK Techniques - |Name|Use| |---|---| - -|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057)|Enumerate processes (This capa rule had 1 match) [[2]](#2) | -|[Discovery::System Service Discovery (T1007)](https://attack.mitre.org/techniques/T1007)|Query service status (This capa rule had 1 match) [[2]](#2) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Link function at runtime on Windows (This capa rule had 1 match) [[2]](#2) | -|[Execution::System Services::Service Execution (T1569.002)](https://attack.mitre.org/techniques/T1569/002)|Interact with driver via control codes (This capa rule had 4 matches) [[2]](#2) | -|[Impact::Service Stop (T1489)](https://attack.mitre.org/techniques/T1489)|Stop service (This capa rule had 1 match) [[2]](#2) | -|[Persistence::Create or Modify System Process::Windows Service (T1543.003)](https://attack.mitre.org/techniques/T1543/003)|Start service (This capa rule had 1 match) [[2]](#2) | +|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057)|Mebromi enumerates processes. [[2]](#2)| +|[Discovery::System Service Discovery (T1007)](https://attack.mitre.org/techniques/T1007)|Mebromi queries a service status. [[2]](#2)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Mebromi links functions at runtime on Windows. [[2]](#2)| +|[Execution::System Services::Service Execution (T1569.002)](https://attack.mitre.org/techniques/T1569/002)|Mebromi interacts with a driver via control codes. [[2]](#2)| +|[Impact::Service Stop (T1489)](https://attack.mitre.org/techniques/T1489)|Mebromi stops services. [[2]](#2)| +|[Persistence::Create or Modify System Process::Windows Service (T1543.003)](https://attack.mitre.org/techniques/T1543/003)|Mebromi starts services. [[2]](#2)| See ATT&CK: [Mebromi - Techniques Used](https://attack.mitre.org/software/S0001/). + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Defense Evasion::Bootkit (F0013)](../defense-evasion/bootkit.md)|An MBR bootkit and a BIOS bootkit targeting Award BIOS. [[1]](#1) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 2 matches) [[2]](#2) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Get file size (This capa rule had 1 match) [[2]](#2) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Check OS version (This capa rule had 1 match) [[2]](#2) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Accept command line arguments (This capa rule had 1 match) [[2]](#2) | +|[Defense Evasion::Bootkit (F0013)](../defense-evasion/bootkit.md)|An MBR bootkit and a BIOS bootkit targeting Award BIOS. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Mebromi encodes data using XOR. [[2]](#2)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Mebromi gets a file size. [[2]](#2)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Mebromi checks OS version. [[2]](#2)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Mebromi accepts command line arguments. [[2]](#2)| ## MBC Behaviors |Name|Use| |---|---| -|[Execution::Conditional Execution (B0025)](../execution/conditional-execution.md)|Malware only proceeds if it detects the BIOS ROM is Award BIOS [[1]](#1) | -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Malware contains a dropper that installs additional programs like Cbrom.exe [[1]](#1) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 2 matches) [[2]](#2) | -|[File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|Copy file (This capa rule had 2 matches) [[2]](#2) | -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 5 matches) [[2]](#2) | -|[File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|Move file (This capa rule had 2 matches) [[2]](#2) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 1 match) [[2]](#2) | -|[Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Allocate RWX memory (This capa rule had 1 match) [[2]](#2) | -|[Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Create process on Windows (This capa rule had 1 match) [[2]](#2) | +|[Execution::Conditional Execution (B0025)](../execution/conditional-execution.md)|Malware only proceeds if it detects the BIOS ROM is Award BIOS. [[1]](#1)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Malware contains a dropper that installs additional programs like Cbrom.exe. [[1]](#1)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Mebromi encodes data using XOR. [[2]](#2)| +|[Micro-Behaviors::File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|Mebromi copies files. [[2]](#2)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Mebromi deletes files. [[2]](#2)| +|[Micro-Behaviors::File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|Mebromi moves files. [[2]](#2)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Mebromi reads files on Windows. [[2]](#2)| +|[Micro-Behaviors::Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Mebromi allocates RWX memory. [[2]](#2)| +|[Micro-Behaviors::Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Mebromi creates a process on Windows. [[2]](#2)| ## Indicators of Compromise diff --git a/xample-malware/netwalker.md b/xample-malware/netwalker.md index 08ba9b0..a3c5811 100644 --- a/xample-malware/netwalker.md +++ b/xample-malware/netwalker.md @@ -2,7 +2,7 @@
IDX0013X0024
Aliases
- + @@ -31,14 +31,15 @@ Fileless ransomware written in PowerShell and executed directly in memory. See ATT&CK: [Netwalker - Techniques Used](https://attack.mitre.org/software/S0457/). + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Execution::Command and Scripting Interpreter (E1049)](../execution/command-and-scripting-interpreter.md)|Netwalker is written and executed in Powershell [[1]](#1)| -|[Defense Evasion::Obfuscated Files or Information (E1027)](../defense-evasion/obfuscated-files-or-information.md)|Netwalker is obfuscated with several layers of encoding, obfuscation, and encryption techniques such as base64, hexademcimal, and XOR [[1]](#1)| -|[Defense Evasion::Process Injection::Dynamic-link Library Injection (E1055.001)](../defense-evasion/process-injection.md)|Netwalker uses reflective DLL loading to inject from memory [[1]](#1)| -|[Impact::Data Encrypted for Impact (E1486)](../impact/data-encrypted-for-impact.md)|Netwalker encrypts files for ransom [[1]](#1)| +|[Execution::Command and Scripting Interpreter (E1049)](../execution/command-and-scripting-interpreter.md)|Netwalker is written and executed in Powershell. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information (E1027)](../defense-evasion/obfuscated-files-or-information.md)|Netwalker is obfuscated with several layers of encoding, obfuscation, and encryption techniques such as Base64, hexademcimal, and XOR. [[1]](#1)| +|[Defense Evasion::Process Injection::Dynamic-link Library Injection (E1055.001)](../defense-evasion/process-injection.md)|Netwalker uses reflective DLL loading to inject from memory. [[1]](#1)| +|[Impact::Data Encrypted for Impact (E1486)](../impact/data-encrypted-for-impact.md)|Netwalker encrypts files for ransom. [[1]](#1)| ## Indicators of Compromise diff --git a/xample-malware/poison-ivy.md b/xample-malware/poison-ivy.md index 4f0eabc..7adc38c 100644 --- a/xample-malware/poison-ivy.md +++ b/xample-malware/poison-ivy.md @@ -1,7 +1,7 @@
IDX0037X0025
Aliases
- + @@ -22,41 +22,46 @@
IDX0014X0026
Aliases
-# Poison-Ivy +# Poison Ivy -Remote Access Trojan (RAT). +Poison Ivy is a Remote Access Trojan (RAT). ## ATT&CK Techniques See ATT&CK: [Poison Ivy - Techniques Used](https://attack.mitre.org/software/S0012/). + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|Code is injected into explorer.exe [[2]](#2) | -|[Collection::Input Capture (E1056)](../collection/input-capture.md)|Can capture audio and video [[2]](#2) | -|[Collection::Keylogging (F0002)](../collection/keylogging.md)|Can capture keystrokes [[2]](#2) | -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|To start itself at system boot, Poison Ivy adds registry entries [[4]](#4) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|After the Poison-Ivy server is running on the target machine, the attacker uses a Windows GUI client to control the target computer [[1]](#1) | -|[Anti-Static Analysis::Obfuscated Files or Information::Encryption of Data (E1027.m07)](../defense-evasion/obfuscated-files-or-information.md)|Poison Ivy variant encrypts all its strings [[3]](#3) | +|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|Code is injected into explorer.exe. [[2]](#2)| +|[Collection::Input Capture (E1056)](../collection/input-capture.md)|Poison Ivy can capture audio and video. [[2]](#2)| +|[Collection::Keylogging (F0002)](../collection/keylogging.md)|Poison Ivy can capture keystrokes. [[2]](#2)| +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|To start itself at system boot, Poison Ivy adds registry entries. [[4]](#4)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|After the Poison Ivy server is running on the target machine, the attacker uses a Windows GUI client to control the target computer. [[1]](#1)| +|[Anti-Static Analysis::Executable Code Obfuscation::Stack Strings (B0032.017)](../anti-static-analysis/executable-code-obfuscation.md)|A Poison Ivy variant encrypts all its strings. [[3]](#3)| +|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|The Poison Ivy implant is run on the target machine. [[2]](#2)| +|[Defense Evasion::Obfuscated Files or Information (E1027)](../defense-evasion/obfuscated-files-or-information.md)|The malware obfuscates files. [[2]](#2)| + ## MBC Behaviors |Name|Use| |---|---| -|[Impact::Remote Access (B0022)](../impact/remote-access.md)|After the Poison-Ivy server is running on the target machine, the attacker uses a Windows GUI client to control the target computer [[1]](#1) | -|[Micro-objective::Cryptography::Encrypt Data::Camellia (C0027.003)](../micro-behaviors/cryptography/encrypt-data.md)|Poison Ivy's custom network protocol over TCP is encrypted using Camellia cipher with a 256-bit key [[2]](#2) | -|[Micro-objective::Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Poison Ivy has a default process mutex, but can be altered at build time [2] [[3]](#3) | -|[Anti-Behavioral Analysis::Debugger Detection::Hardware Breakpoints (B0001.005)](../anti-behavioral-analysis/debugger-detection.md)|Poison Ivy Variant checks for breakpoints and exits immediately if found [[3]](#3) | -|[Discovery::Analysis Tool Discovery (B0013)](../discovery/analysis-tool-discovery.md)|Poison Ivy Variant runs a threat to check if any analysis tools are running by creating specially named pipes that are created by various analysis tools. If one of the named pipes cannot be created, it means one fo the analysis tools is running. [[3]](#3) | -|[Discovery::Analysis Tool Discovery::Known Windows Class Name (B0013.010)](../discovery/analysis-tool-discovery.md)|Poison Ivy variant goes through all the running program windows to check if any windows class name contains a special string to determine if an analysis tool is running [[3]](#3) | -|[Process::Micro-objective::Check Mutex (C0043)](../micro-behaviors/process/check-mutex.md)|Poison Ivy variant checks if the wireshark-is-running{} named mutex object exists [[3]](#3) | -|[Anti-Behavioral Analysis::Debugger Detection::IsDebuggerPresent (B0001.008)](../anti-behavioral-analysis/debugger-detection.md)|Poison Ivy variant uses the IsDebuggerPresent API function call to check if the process is running in a debugger [[3]](#3) | -|[Communication::Interprocess Communication::Write Pipe (C0003.004)](../micro-behaviors/communication/interprocess-communication.md)|Write pipe (This capa rule had 1 match) [[5]](#5) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 1 match) [[5]](#5) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Write file on Windows (This capa rule had 1 match) [[5]](#5) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 1 match) [[5]](#5) | +|[Impact::Remote Access (B0022)](../impact/remote-access.md)|After the Poison Ivy server is running on the target machine, the attacker uses a Windows GUI client to control the target computer. [[1]](#1)| +|[Micro-Behaviors::Cryptography::Encrypt Data::Camellia (C0027.003)](../micro-behaviors/cryptography/encrypt-data.md)|Poison Ivy's custom network protocol over TCP is encrypted using Camellia cipher with a 256-bit key. [[2]](#2)| +|[Micro-Behaviors::Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Poison Ivy has a default process mutex, but it can be altered at build time. [[3]](#3)| +|[Anti-Behavioral Analysis::Debugger Detection::Hardware Breakpoints (B0001.005)](../anti-behavioral-analysis/debugger-detection.md)|A Poison Ivy variant checks for breakpoints and exits immediately if found. [[3]](#3)| +|[Discovery::Analysis Tool Discovery (B0013)](../discovery/anlaysis-tool-discovery.md)|A Poison Ivy variant runs a thread to check if any analysis tools are running by creating specially named pipes that are created by various analysis tools. If one of the named pipes cannot be created, it means one of the analysis tools is running. [[3]](#3)| +|[Discovery::Analysis Tool Discovery::Known Windows Class Name (B0013.010)](../discovery/analysis-tool-discovery.md)|A Poison Ivy variant goes through all the running program windows to check if any Windows class name contains a special string to determine if an analysis tool is running. [[3]](#3)| +|[Micro-Behaviors::Process::Check Mutex (C0043)](../micro-behaviors/process/check-mutex.md)|A Poison Ivy variant checks if the wireshark-is-running{} named mutex object exists. [[3]](#3)| +|[Anti-Behavioral Analysis::Debugger Detection::IsDebuggerPresent (B0001.008)](../anti-behavioral-analysis/debugger-detection.md)|A Poison Ivy variant uses the IsDebuggerPresent API function call to check if the process is running in a debugger. [[3]](#3)| +|[Micro-Behaviors::Communication::Interprocess Communication::Write Pipe (C0003.004)](../micro-behaviors/communication/interprocess-communication.md)|Poison Ivy writes pipes. [[5]](#5)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Poison Ivy reads files on Windows. [[5]](#5)| +|[Micro-Behaviors::File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Poison Ivy writes files on Windows. [[5]](#5)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Poison Ivy queries or enumerates registry values. [[5]](#5)| + ## Indicators of Compromise diff --git a/xample-malware/rebhip.md b/xample-malware/rebhip.md deleted file mode 100644 index 0434bc9..0000000 --- a/xample-malware/rebhip.md +++ /dev/null @@ -1,99 +0,0 @@ - - - - - - - - - - - - - - - - - - - - - -
IDX0015
AliasesNone
PlatformsWindows
Year2011
Associated ATT&CK SoftwareNone
- - -# Redhip - -An information stealer. - -## ATT&CK Techniques - -|Name|Use| -|---|---| -|[Credential Access::Credentials from Password Stores::Windows Credential Manager (T1555.004)](https://attack.mitre.org/techniques/T1555/004)|Acquire credentials from Windows Credential Manager (This capa rule had 3 matches) [[2]](#2) | -|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Set file attributes (This capa rule had 1 match) [[2]](#2) | -|[Defense Evasion::Virtualization/Sandbox Evasion::System Checks (T1497.001)](https://attack.mitre.org/techniques/T1497/001)|Reference anti-VM strings targeting VirtualBox (This capa rule had 1 match) [[2]](#2) | -|[Discovery::Account Discovery (T1087)](https://attack.mitre.org/techniques/T1087)|Get user security identifier (This capa rule had 1 match) [[2]](#2) | -|[Discovery::System Owner/User Discovery (T1033)](https://attack.mitre.org/techniques/T1033)|Get session user name (This capa rule had 3 matches) [[2]](#2) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Access PEB ldr_data (This capa rule had 1 match) [[2]](#2) | - - -## Enhanced ATT&CK Techniques - -|Name|Use| -|---|---| -|[Anti-Static Analysis::Software Packing (F0001)](../anti-static-analysis/software-packing.md)|Redhip samples are packed with different custom packers. [[1]](#1) | -|[Collection::Keylogging::Application Hook (F0002.001)](../collection/keylogging.md)|Log keystrokes via application hook (This capa rule had 1 match) [[2]](#2) | -|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|Log keystrokes via polling (This capa rule had 1 match) [[2]](#2) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 1 match) [[2]](#2) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Get file size (This capa rule had 3 matches) [[2]](#2) | -|[Persistence::Registry Run Keys / Startup Folder (E1547.001)](../persistence/registry-run-keys-startup-folder.md)|Persist via Run registry key (This capa rule had 4 matches) [[2]](#2) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Check OS version (This capa rule had 1 match) [[2]](#2) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Accept command line arguments (This capa rule had 1 match) [[2]](#2) | -|[Defense Evasion::Process Injection::Thread Execution Hijacking (E1055.003)](../defense-evasion/process-injection.md)|Inject thread (This capa rule had 1 match) [[2]](#2) | - -## MBC Behaviors - -|Name|Use| -|---|---| -|[Anti-Behavioral Analysis::Sandbox Detection::Product Key/ID Testing (B0007.005)](../anti-behavioral-analysis/sandbox-detection.md)|Redhip detects all publicly available automated malware analysis workbenches (ThreatExpert, JoeBox, etc.) by considering OS product keys and special DLLs. [[1]](#1) check for sandbox and av modules (This capa rule had 2 matches) [[2]](#2) | -|[Anti-Behavioral Analysis::Virtual Machine Detection (B0009)](../anti-behavioral-analysis/virtual-machine-detection.md)|Redhip detects VMWare, Virtual PC and Virtual Box. It also detects VM environments in general by considering timing lapses. [[1]](#1) | -|[Anti-Behavioral Analysis::Debugger Detection (B0001)](../anti-behavioral-analysis/debugger-detection.md)|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFICE. [[1]](#1) | -|[Anti-Behavioral Analysis::Debugger Evasion (B0002)](../anti-behavioral-analysis/debugger-evasion.md)|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFICE. [[1]](#1) | -|[Anti-Behavioral Analysis::Debugger Detection::Process Environment Block BeingDebugged (B0001.035)](../anti-behavioral-analysis/debugger-detection.md)|Check for PEB BeingDebugged flag (This capa rule had 6 matches) [[2]](#2) | -|[Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)](../anti-behavioral-analysis/debugger-detection.md)|Check for time delay via GetTickCount (This capa rule had 1 match) [[2]](#2) | -|[Cryptography::Cryptographic Hash (C0029)](../micro-behaviors/cryptography/cryptographic-hash.md)|Hash data via WinCrypt (This capa rule had 1 match) [[2]](#2) | -|[Cryptography::Cryptographic Hash::SHA1 (C0029.002)](../micro-behaviors/cryptography/cryptographic-hash.md)|Hash data using SHA1 (This capa rule had 1 match) [[2]](#2) | -|[Cryptography::Encrypt Data (C0027)](../micro-behaviors/cryptography/encrypt-data.md)|Encrypt data using DPAPI (This capa rule had 6 matches) [[2]](#2) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 1 match) [[2]](#2) | -|[Discovery::Code Discovery::Inspect Section Memory Permissions (B0046.002)](../discovery/code-discovery.md)|Inspect section memory permissions (This capa rule had 1 match) [[2]](#2) | -|[Discovery::Taskbar Discovery (B0043)](../discovery/taskbar-discovery.md)|Find taskbar (This capa rule had 1 match) [[2]](#2) | -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Contain an embedded PE file (This capa rule had 1 match) [[2]](#2) | -|[File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|Copy file (This capa rule had 2 matches) [[2]](#2) | -|[File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|Create directory (This capa rule had 1 match) [[2]](#2) | -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 2 matches) [[2]](#2) | -|[File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|Get file attributes (This capa rule had 2 matches) [[2]](#2) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 3 matches) [[2]](#2) | -|[File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|Set file attributes (This capa rule had 1 match) [[2]](#2) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Write file on Windows (This capa rule had 1 match) [[2]](#2) | -|[Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Spawn thread to RWX shellcode (This capa rule had 1 match) [[2]](#2) | -|[Operating System::Registry::Delete Registry Key (C0036.002)](../micro-behaviors/operating-system/registry.md)|Delete registry key (This capa rule had 2 matches) [[2]](#2) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 9 matches) [[2]](#2) | -|[Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Set registry value (This capa rule had 4 matches) [[2]](#2) | -|[Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Create mutex (This capa rule had 1 match) [[2]](#2) | -|[Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Create process on Windows (This capa rule had 10 matches) [[2]](#2) | -|[Process::Create Process::Create Suspended Process (C0017.003)](../micro-behaviors/process/create-process.md)|Create process suspended (This capa rule had 10 matches) [[2]](#2) | -|[Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|Set thread local storage value (This capa rule had 1 match) [[2]](#2) | - -## Indicators of Compromise - -SHA256 Hashes -- 07b8f25e7b536f5b6f686c12d04edc37e11347c8acd5c53f98a174723078c365 -- 65853e6a70b50166b2e2bd1e163d420d1184ff865183c5f68d8e8bb83eff3e6d - -## References - -[1] https://web.archive.org/web/20161025013916/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html - -[2] capa v4.0, analyzed at MITRE on 10/12/2022 - diff --git a/xample-malware/redhip.md b/xample-malware/redhip.md new file mode 100644 index 0000000..83fffec --- /dev/null +++ b/xample-malware/redhip.md @@ -0,0 +1,100 @@ + + + + + + + + + + + + + + + + + + + + + +
IDX0027
AliasesNone
PlatformsWindows
Year2011
Associated ATT&CK SoftwareNone
+ + +# Redhip + +Redhip is an information stealer. + +## ATT&CK Techniques + +|Name|Use| +|---|---| +|[Credential Access::Credentials from Password Stores::Windows Credential Manager (T1555.004)](https://attack.mitre.org/techniques/T1555/004)|Redhip acquires credentials from Windows Credential Manager. [[2]](#2)| +|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Redhip sets file attributes. [[2]](#2)| +|[Defense Evasion::Virtualization/Sandbox Evasion::System Checks (T1497.001)](https://attack.mitre.org/techniques/T1497/001)|Redhip references anti-VM strings targeting VirtualBox. [[2]](#2)| +|[Discovery::Account Discovery (T1087)](https://attack.mitre.org/techniques/T1087)|Redhip gets a user security identifier. [[2]](#2)| +|[Discovery::System Owner/User Discovery (T1033)](https://attack.mitre.org/techniques/T1033)|Redhip gets a session user name. [[2]](#2)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Redhip accesses PEB ldr_data. [[2]](#2)| + + +## Enhanced ATT&CK Techniques + +|Name|Use| +|---|---| +|[Anti-Static Analysis::Software Packing (F0001)](../anti-static-analysis/software-packing.md)|Redhip samples are packed with different custom packers. [[1]](#1)| +|[Collection::Keylogging::Application Hook (F0002.001)](../collection/keylogging.md)|Redhip logs keystrokes via application hook. [[2]](#2)| +|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|Redhip logs keystrokes via polling. [[2]](#2)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Redhip encodes data using XOR. [[2]](#2)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Redhip gets a file size. [[2]](#2)| +|[Persistence::Registry Run Keys / Startup Folder (E1547.001)](../persistence/registry-run-keys-startup-folder.md)|Redhip persists via a Run registry key. [[2]](#2)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Redhip checks the OS version. [[2]](#2)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Redhip accepts command line arguments. [[2]](#2)| +|[Defense Evasion::Process Injection::Thread Execution Hijacking (E1055.003)](../defense-evasion/process-injection.md)|Redhip injects threads. [[2]](#2)| + +## MBC Behaviors + +|Name|Use| +|---|---| +|[Anti-Behavioral Analysis::Sandbox Detection::Product Key/ID Testing (B0007.005)](../anti-behavioral-analysis/sandbox-detection.md#b0007005)|Redhip detects all publicly available automated malware analysis workbenches (ThreatExpert, JoeBox, etc.) by considering OS product keys and special DLLs and checks for sandboxes and AV modules. [[1]](#1) [[2]](#2)| +|[Anti-Behavioral Analysis::Virtual Machine Detection (B0009)](../anti-behavioral-analysis/virtual-machine-detection.md)|Redhip detects VMWare, Virtual PC, and Virtual Box. It also detects VM environments in general by considering time lapses. [[1]](#1)| +|[Anti-Behavioral Analysis::Debugger Detection (B0001)](../anti-behavioral-analysis/debugger-detection.md)|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFTICE. [[1]](#1)| +|[Anti-Behavioral Analysis::Debugger Evasion (B0002)](../anti-behavioral-analysis/debugger-evasion.md)|Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFTICE. [[1]](#1)| +|[Anti-Behavioral Analysis::Debugger Detection::Process Environment Block BeingDebugged (B0001.035)](../anti-behavioral-analysis/debugger-detection.md)|Redhip checks for PEB BeingDebugged flag. [[2]](#2)| +|[Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)](../anti-behavioral-analysis/debugger-detection.md)|Redhip checks for time delay via GetTickCount. [[2]](#2)| +|[Micro-Behaviors::Cryptography::Cryptographic Hash (C0029)](../micro-behaviors/cryptography/cryptographic-hash.md)|Redhip hashes data via WinCrypt. [[2]](#2)| +|[Micro-Behaviors::Cryptography::Cryptographic Hash::SHA1 (C0029.002)](../micro-behaviors/cryptography/cryptographic-hash.md)|Redhip hashes data using SHA1. [[2]](#2)| +|[Micro-Behaviors::Cryptography::Encrypt Data (C0027)](../micro-behaviors/cryptography/encrypt-data.md)|Redhip encrypts data using DPAPI. [[2]](#2)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Redhip encodes data using XOR. [[2]](#2)| +|[Discovery::Code Discovery::Inspect Section Memory Permissions (B0046.002)](../discovery/code-discovery.md)|Redhip inspects section memory permissions. [[2]](#2)| +|[Discovery::Taskbar Discovery (B0043)](../discovery/taskbar-discovery.md)|Redhip finds taskbars. [[2]](#2)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Redhip contains an embedded PE file. [[2]](#2)| +|[Micro-Behaviors::File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|Redhip copies files. [[2]](#2)| +|[Micro-Behaviors::File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|Redhip creates directories. [[2]](#2)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Redhip deletes files. [[2]](#2)| +|[Micro-Behaviors::File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|Redhip gets file attributes. [[2]](#2)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Redhip reads files on Windows. [[2]](#2)| +|[Micro-Behaviors::File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|Redhip sets file attributes. [[2]](#2)| +|[Micro-Behaviors::File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Redhip writes files on Windows. [[2]](#2)| +|[Micro-Behaviors::Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Redhip spawns threads to RWX shellcode. [[2]](#2)| +|[Micro-Behaviors::Operating System::Registry::Delete Registry Key (C0036.002)](../micro-behaviors/operating-system/registry.md)|Redhip deletes registry keys. [[2]](#2)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Redhip queries or enumerates registry values. [[2]](#2)| +|[Micro-Behaviors::Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Redhip sets registry values. [[2]](#2)| +|[Micro-Behaviors::Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Redhip creates a mutex. [[2]](#2)| +|[Micro-Behaviors::Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Redhip creates a process on Windows. [[2]](#2)| +|[Micro-Behaviors::Process::Create Process::Create Suspended Process (C0017.003)](../micro-behaviors/process/create-process.md)|Redhip creates a suspended process. [[2]](#2)| +|[Micro-Behaviors::Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|Redhip sets thread local storage values. [[2]](#2)| + + +## Indicators of Compromise + +SHA256 Hashes +- 07b8f25e7b536f5b6f686c12d04edc37e11347c8acd5c53f98a174723078c365 +- 65853e6a70b50166b2e2bd1e163d420d1184ff865183c5f68d8e8bb83eff3e6d + +## References + +[1] https://web.archive.org/web/20161025013916/https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html + +[2] capa v4.0, analyzed at MITRE on 10/12/2022 + diff --git a/xample-malware/rombertik.md b/xample-malware/rombertik.md index ccd341d..13bba66 100644 --- a/xample-malware/rombertik.md +++ b/xample-malware/rombertik.md @@ -1,7 +1,7 @@ - + @@ -31,72 +31,74 @@ This family of malware steals data the user enters into a browser and uses a var |Name|Use| |---|---| -|[Initial Access::Phishing::Spearphishing Attachment (T1566.001)](https://attack.mitre.org/techniques/T1566/001/)|The malware is sent out to victims via an attachment [[1]](#1) | -|[Defense Evasion::Deobfuscate/Decode Files or Information (T1140)](https://attack.mitre.org/techniques/T1140/)|The malware will unpack its code in memory [[1]](#1) | -|[Impact::Disk Wipe (T1561)](https://attack.mitre.org/techniques/T1561/)|If a specific anti-analysis check fails, the malware will overwrite the Master Boot Record or the User's home folder [[1]](#1) | -|[Command and Control::Data Encoding::Standard Encoding (T1132.001)](https://attack.mitre.org/techniques/T1132/001/)|The malware transmits Base64 encoded data to C2 [[1]](#1) | -|[Command and Control::Application Layer Protocol::Web Protocols (T1071.001)](https://attack.mitre.org/techniques/T1071/001/)|The malware transmits data over HTTP [[1]](#1) | -|[Collection::Clipboard Data (T1115)](https://attack.mitre.org/techniques/T1115)|Read clipboard data (This capa rule had 1 match) [[2]](#2) | -|[Defense Evasion::Hide Artifacts::Hidden Window (T1564.003)](https://attack.mitre.org/techniques/T1564/003)|Hide graphical window (This capa rule had 7 matches) [[2]](#2) | -|[Discovery::Account Discovery (T1087)](https://attack.mitre.org/techniques/T1087)|Get session user name (This capa rule had 1 match) [[2]](#2) | -|[Discovery::Application Window Discovery (T1010)](https://attack.mitre.org/techniques/T1010)|Enumerate gui resources (This capa rule had 2 matches) [[2]](#2) | -|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057)|Get process heap force flags (This capa rule had 1 match) [[2]](#2) | -|[Discovery::System Location Discovery (T1614)](https://attack.mitre.org/techniques/T1614)|Get geographical location (This capa rule had 5 matches) [[2]](#2) | -|[Discovery::System Location Discovery::System Language Discovery (T1614.001)](https://attack.mitre.org/techniques/T1614/001)|Get keyboard layout (This capa rule had 2 matches) [[2]](#2) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Access PEB ldr_data (This capa rule had 8 matches) [[2]](#2) | +|[Initial Access::Phishing::Spearphishing Attachment (T1566.001)](https://attack.mitre.org/techniques/T1566/001/)|The malware is sent out to victims via an attachment. [[1]](#1)| +|[Persistence::Boot or Logon Autostart Execution (T1547)](https://attack.mitre.org/techniques/T1547/)|The malware starts everytime a user logs in. [[1]](#1)| +|[Defense Evasion::Deobfuscate/Decode Files or Information (T1140)](https://attack.mitre.org/techniques/T1140/)|The malware will unpack its code in memory. [[1]](#1)| +|[Impact::Disk Wipe (T1561)](https://attack.mitre.org/techniques/T1561/)|If a specific anti-analysis check fails, the malware will overwrite the Master Boot Record or the user's home folder. [[1]](#1)| +|[Command and Control::Data Encoding::Standard Encoding (T1132.001)](https://attack.mitre.org/techniques/T1132/001/)|The malware transmits Base64 encoded data to C2. [[1]](#1)| +|[Command and Control::Application Layer Protocol::Web Protocols (T1071.001)](https://attack.mitre.org/techniques/T1071/001/)|The malware transmits data over HTTP. [[1]](#1)| +|[Collection::Clipboard Data (T1115)](https://attack.mitre.org/techniques/T1115)|Rombertik reads clipboard data. [[2]](#2)| +|[Defense Evasion::Hide Artifacts::Hidden Window (T1564.003)](https://attack.mitre.org/techniques/T1564/003)|Rombertik hides graphical windows. [[2]](#2)| +|[Discovery::Account Discovery (T1087)](https://attack.mitre.org/techniques/T1087)|Rombertik gets a session user name. [[2]](#2)| +|[Discovery::Application Window Discovery (T1010)](https://attack.mitre.org/techniques/T1010)|Rombertik enumerates GUI resources. [[2]](#2)| +|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057)|Rombertik gets process heap force flags. [[2]](#2)| +|[Discovery::System Location Discovery (T1614)](https://attack.mitre.org/techniques/T1614)|Rombertik gets geographical locations. [[2]](#2)| +|[Discovery::System Location Discovery::System Language Discovery (T1614.001)](https://attack.mitre.org/techniques/T1614/001)|Rombertik gets keyboard layout. [[2]](#2)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Rombertik accesses PEB ldr_data. [[2]](#2)| ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Execution::User Execution (E1204)](../execution/user-execution.md)|The malware relies on a victim to execute itself [[1]](#1) | -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|The malware will proceed to install itself in order to ensure persistence across system reboots before continuing on to execute the payload. To install itself, Rombertik first creates a VBS script named “fgf.vbs”, which is used to kick off [[1]](#1) | -|[Collection::Input Capture (E1056)](../collection/input-capture.md)|The malware injects itself into a browser and captures user input data [[1]](#1) | -|[Impact::Data Destruction (E1485)](../impact/data-destruction.md)|If a specific anti-analysis check fails, the malware will overwrite the Master Boot Record or the User's home folder [[1]](#1) | -|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|Log keystrokes via polling (This capa rule had 7 matches) [[2]](#2) | -|[Collection::Screen Capture::WinAPI (E1113.m01)](../collection/screen-capture.md)|Capture screenshot (This capa rule had 2 matches) [[2]](#2) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 5 matches) [[2]](#2) | -|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|Get graphical window text (This capa rule had 2 matches) [[2]](#2) | -|[Impact::Clipboard Modification (E1510)](../impact/clipboard-modification.md)|Replace clipboard data (This capa rule had 1 match) [[2]](#2) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Get file version info (This capa rule had 1 match) [[2]](#2) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Get disk size (This capa rule had 1 match) [[2]](#2) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Accept command line arguments (This capa rule had 1 match) [[2]](#2) | +|[Execution::User Execution (E1204)](../execution/user-execution.md)|The malware relies on a victim to execute itself. [[1]](#1)| +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|The malware will proceed to install itself in order to ensure persistence across system reboots before continuing on to execute the payload. To install itself, Rombertik first creates a VBS script named “fgf.vbs”, which is used to kick off Rombertik every time the user logs in, and places the script into the user’s Startup folder. [[1]](#1)| +|[Collection::Input Capture (E1056)](../collection/input-capture.md)|The malware injects itself into a browser and captures user input data. [[1]](#1)| +|[Impact::Data Destruction (E1485)](../impact/data-destruction.md)|If a specific anti-analysis check fails, the malware will overwrite the Master Boot Record or the user's home folder. [[1]](#1)| +|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|Rombertik logs keystrokes via polling. [[2]](#2)| +|[Collection::Screen Capture::WinAPI (E1113.m01)](../collection/screen-capture.md)|Rombertik captures screenshots. [[2]](#2)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Rombertik encodes data using XOR. [[2]](#2)| +|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|Rombertik gets graphical window texts. [[2]](#2)| +|[Impact::Clipboard Modification (E1510)](../impact/clipboard-modification.md)|Rombertik replaces clipboard data. [[2]](#2)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Rombertik gets file version info. [[2]](#2)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Rombertik gets disk sizes. [[2]](#2)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Rombertik accepts command line arguments. [[2]](#2)| + ## MBC Behaviors |Name|Use| |---|---| -|[Anti-Static Analysis::Executable Code Obfuscation::Code Insertion (B0032.002)](../anti-static-analysis/executable-code-obfuscation.md)|Most of the malware file consists of unnecessary code or unnecessary data [[1]](#1) | -|[Anti-Behavior Analysis::Dynamic Analysis Evasion::Data Flood (B0003.002)](../anti-behavioral-analysis/dynamic-analysis-evasion.md)|The malware stalls by writing a byte of random data to memory 960 million times which complicates analysis. It also calls specific Windows API functions [[1]](#1) | -|[Anti-Behavioral Analysis::Sandbox Detection::Test API Routines (B0007.010)](../anti-behavioral-analysis/virtual-machine-detection.md)|The malware check for sandboxes that suppress errors returned from API routine calls the using ZwGetWriteWatch routine. [[1]](#1) | -|[Anti-Behavioral Analysis::Debugger Detection::OutputDebugString (B0001.016)](../anti-behavioral-analysis/virtual-machine-detection.md)|The malware calls the Windows API OutputDebugString function 335,000 times [[1]](#1) | -|[Anti-Behavior Analysis::Debugger Detection::Check Processes (B0001.038)](../anti-behavioral-analysis/virtual-machine-detection.md)|An anti-analysis function within the packer is called to check the username and filename of the executing process for strings like “malwar”, “sampl”, “viru”, and “sandb”. [[1]](#1) | -|[Anti-Behavioral Anlaysis::Dynamic Analysis Evasion::Code Integrity Check (B0003.011)](../anti-behavioral-analysis/dynamic-analysis-evasion.md)|The function computes a 32-bit hash of a resource in memory, and compares it to the PE Compile Timestamp of the unpacked sample. If the resource or compile time has been altered, the malware acts destructively [[1]](#1) | -|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/domain-name-generation.md)|The malware sends data to the C2 [[1]](#1) | -|[Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)](../anti-behavioral-analysis/debugger-detection.md)|Check for time delay via GetTickCount (This capa rule had 3 matches) [[2]](#2) | -|[Anti-Static Analysis::Disassembler Evasion::Argument Obfuscation (B0012.001)](../anti-static-analysis/disassembler-evasion.md)|Contain obfuscated stackstrings (This capa rule had 1 match) [[2]](#2) | -|[Command And Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|Receive data (This capa rule had 6 matches) [[2]](#2) | -|[Command And Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|Send data (This capa rule had 1 match) [[2]](#2) | -|[Communication::Socket Communication::Create TCP Socket (C0001.011)](../micro-behaviors/communication/socket-communication.md)|Create TCP socket (This capa rule had 1 match) [[2]](#2) | -|[Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Encrypt data using RC4 PRGA (This capa rule had 1 match) [[2]](#2) | -|[Cryptography::Encryption Key::RC4 KSA (C0028.002)](../micro-behaviors/cryptography/encryption-key.md)|Encrypt data using RC4 KSA (This capa rule had 1 match) [[2]](#2) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 5 matches) [[2]](#2) | -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 1 match) [[2]](#2) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 3 matches) [[2]](#2) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Write file on Windows (This capa rule had 4 matches) [[2]](#2) | -|[Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Allocate RWX memory (This capa rule had 2 matches) [[2]](#2) | -|[Operating System::Registry::Delete Registry Key (C0036.002)](../micro-behaviors/operating-system/registry.md)|Delete registry key (This capa rule had 1 match) [[2]](#2) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 5 matches) [[2]](#2) | -|[Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Set registry value (This capa rule had 1 match) [[2]](#2) | -|[Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Create mutex (This capa rule had 1 match) [[2]](#2) | -|[Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|Create thread (This capa rule had 1 match) [[2]](#2) | -|[Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|Set thread local storage value (This capa rule had 1 match) [[2]](#2) | +|[Anti-Static Analysis::Executable Code Obfuscation::Code Insertion (B0032.002)](../anti-static-analysis/executable-code-obfuscation.md)|Most of the malware file consists of unnecessary code or unnecessary data. [[1]](#1)| +|[Anti-Behavior Analysis::Dynamic Analysis Evasion::Data Flood (B0003.002)](../anti-behavioral-analysis/dynamic-analysis-evasion.md)|The malware stalls by writing a byte of random data to memory 960 million times which complicates analysis. It also calls specific Windows API functions. [[1]](#1)| +|[Anti-Behavioral Analysis::Sandbox Detection::Test API Routines (B0007.010)](../anti-behavioral-analysis/virtual-machine-detection.md)|The malware checks for sandboxes that suppress errors returned from API routine calls the using ZwGetWriteWatch routine. [[1]](#1)| +|[Anti-Behavioral Analysis::Debugger Detection::OutputDebugString (B0001.016)](../anti-behavioral-analysis/virtual-machine-detection.md)|The malware calls the Windows API OutputDebugString function 335,000 times. [[1]](#1)| +|[Anti-Behavior Analysis::Debugger Detection::Check Processes (B0001.038)](../anti-behavioral-analysis/virtual-machine-detection.md)|An anti-analysis function within the packer is called to check the username and filename of the executing process for strings like “malwar”, “sampl”, “viru”, and “sandb”. [[1]](#1)| +|[Anti-Behavioral Anlaysis::Dynamic Analysis Evasion::Code Integrity Check (B0003.011)](../anti-behavioral-analysis/dynamic-analysis-evasion.md)|The function computes a 32-bit hash of a resource in memory and compares it to the PE Compile Timestamp of the unpacked sample. If the resource or compile time has been altered, the malware acts destructively. [[1]](#1)| +|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/domain-name-generation.md)|The malware sends data to the C2. [[1]](#1) [[2]](#2)| +|[Command And Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|Rombertik receives data. [[2]](#2)| +|[Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)](../anti-behavioral-analysis/debugger-detection.md)|Rombertik checks for time delay via GetTickCount. [[2]](#2)| +|[Anti-Static Analysis::Disassembler Evasion::Argument Obfuscation (B0012.001)](../anti-static-analysis/disassembler-evasion.md)|Rombertik contains obfuscated stack strings. [[2]](#2)| +|[Micro-Behaviors::Communication::Socket Communication::Create TCP Socket (C0001.011)](../micro-behaviors/communication/socket-communication.md)|Rombertik creates TCP sockets. [[2]](#2)| +|[Micro-Behaviors::Cryptography::Encrypt Data::RC4 (C0027.009)](../micro-behaviors/cryptography/encrypt-data.md)|Rombertik encrypts data using RC4 PRGA. [[2]](#2)| +|[Micro-Behaviors::Cryptography::Encryption Key::RC4 KSA (C0028.002)](../micro-behaviors/cryptography/encryption-key.md)|Rombertik encrypts data using RC4 KSA. [[2]](#2)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Rombertik encodes data using XOR. [[2]](#2)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Rombertik deletes files. [[2]](#2)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Rombertik reads files on Windows. [[2]](#2)| +|[Micro-Behaviors::File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Rombertik writes files on Windows. [[2]](#2)| +|[Micro-Behaviors::Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Rombertik allocates RWX memory. [[2]](#2)| +|[Micro-Behaviors::Operating System::Registry::Delete Registry Key (C0036.002)](../micro-behaviors/operating-system/registry.md)|Rombertik deletes registry keys. [[2]](#2)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Rombertik queries or enumerates registry values. [[2]](#2)| +|[Micro-Behaviors::Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Rombertik sets registry values. [[2]](#2)| +|[Micro-Behaviors::Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Rombertik creates a mutex. [[2]](#2)| +|[Micro-Behaviors::Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|Rombertik creates a thread. [[2]](#2)| +|[Micro-Behaviors::Process::Set Thread Local Storage Value (C0041)](../micro-behaviors/process/set-thread-local-storage-value.md)|Rombertik sets thread local storage values. [[2]](#2)| ## Indicators of Compromise SHA256 Hashes - 0d11a13f54d6003a51b77df355c6aa9b1d9867a5af7661745882b61d9b75bccf - 77bacb44132eba894ff4cb9c8aa50c3e9c6a26a08f93168f65c48571fdf48e2a + Command-and-Control Servers - www.centozos[.]org[.]in diff --git a/xample-malware/samsam.md b/xample-malware/samsam.md index 8e7a8ed..8db0c30 100644 --- a/xample-malware/samsam.md +++ b/xample-malware/samsam.md @@ -1,7 +1,7 @@
IDX0031X0028
Aliases
- + @@ -24,7 +24,7 @@ # SamSam -Ransomware. +SamSam is ransomware. ## ATT&CK Techniques @@ -35,19 +35,22 @@ See ATT&CK: [SamSam - Techniques Used](https://attack.mitre.org/software/S0370/) |Name|Use| |---|---| -|[Impact::Data Encrypted for Impact (E1486)](../impact/data-encrypted-for-impact.md)|SamSam encrypts data to hold for ransom [[1]](#1) | -|[Execution::Exploitation for Client Execution::Remote Desktop Protocols (E1203.m01)](../execution/exploitation-for-client-execution.md)|SamSam uses RDP to maintain persistence [[1]](#1) | -|[Defense Evasion::Obfuscated Files or Information::Encryption of Code (E1027.m07)](../defense-evasion/obfuscated-files-or-information.md)|SamSam obfuscates functions, class names and strings, including the list of targeted file extensions, the help file contents and environment variables using DES encryption with a fixed hard-coded key and the IV [[2]](#2) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|SamSam uses a batch file for executing the malware and deleting certain components [[3]](#3) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Enumerate files on windows (This capa rule had 1 match) [[4]](#4) | +|[Impact::Data Encrypted for Impact (E1486)](../impact/data-encrypted-for-impact.md)|SamSam encrypts data to hold for ransom. [[1]](#1)| +|[Execution::Exploitation for Client Execution::Remote Desktop Protocols (E1203.m01)](../execution/exploitation-for-client-execution.md)|Attackers associated with SamSam exploit vulnerabilities in remote desktop protocols (RDP), Java-based web servers, or file transfer protocol (FTP) servers. [[5]](#5)| +|[Anti-Static Analysis::Executable Code Obfuscation (B0032)](../anti-static-analysis/executable-code-obfuscation.md)|SamSam obfuscates functions, class names and strings, including the list of targeted file extensions, the help file contents and environment variables using DES encryption with a fixed hard-coded key and the IV. [[2]](#2)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|SamSam uses a batch file for executing the malware and deleting certain components. [[3]](#3)| +|[Defense Evasion::Obfuscated Files or Information::Encryption of Code (E1027.m07)](../defense-evasion/obfuscated-files-or-information.md)|SamSam obfuscates functions, class names and strings, including the list of targeted file extensions, the help file contents and environment variables using DES encryption with a fixed hard-coded key and the IV. [[2]](#2)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|SamSam enumerates files on Windows. [[4]](#4)| ## MBC Behaviors |Name|Use| |---|---| -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 1 match) [[4]](#4) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 1 match) [[4]](#4) | +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|SamSam deletes files. [[4]](#4)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|SamSam reads files on Windows. [[4]](#4)| + + ## Indicators of Compromise @@ -70,6 +73,7 @@ BTC Wallet Tor Onion Service - jcmi5n4c3mvgtyt5.onion + ## References [1] https://www.cisa.gov/uscert/ncas/alerts/AA18-337A @@ -80,3 +84,4 @@ Tor Onion Service [4] capa v4.0, analyzed at MITRE on 10/12/2022 +[5] https://blog.malwarebytes.com/cybercrime/2018/05/samsam-ransomware-need-know/ diff --git a/xample-malware/searchawesome.md b/xample-malware/searchawesome.md index 65a80f9..7611748 100644 --- a/xample-malware/searchawesome.md +++ b/xample-malware/searchawesome.md @@ -2,7 +2,7 @@
IDX0016X0029
Aliases
- + @@ -25,25 +25,26 @@ # SearchAwesome -Adware that intercepts encrypted web traffic to inject ads. +SearchAwesome adware intercepts encrypted web traffic to inject ads. ## ATT&CK Techniques |Name|Use| |---|---| -|[Defense Evasion::Subvert Trust Controls (T1553)](https://attack.mitre.org/techniques/T1553/)|The malware uses certificates to gain access to https traffic. [[1]](#1)| +|[Defense Evasion::Subvert Trust Controls (T1553)](https://attack.mitre.org/techniques/T1553/)|The malware uses certificates to gain access to HTTPS traffic. [[1]](#1)| |[Collection::Browser Session Hijacking (T1185)](https://attack.mitre.org/techniques/T1185/)|The malware can modify web traffic for the purpose of injecting Javascript. [[1]](#1)| |[Command and Control::Proxy (T1090)](https://attack.mitre.org/techniques/T1090/)|The malware uses mitmproxy to intercept and modify web traffic. [[1]](#1)| |[Collection::Adversary-in-the-Middle (T1557)](https://attack.mitre.org/techniques/T1557/)|After installing a certificate, the malware inserts inself into a chain of custody, typically within network packets. [[1]](#1)| + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Execution::User Execution (E1204)](../execution/user-execution.md)|A user must execute the malicious program. [[1]](#1)| -|[Defense Evasion::Self Deletion (F0007)](../defense-evasion/self-deletion.md)|The malware will monitor if a specific file gets deleted, and then will delete itself. [[1]](#1)| +|[Execution::User Execution (E1204)](../execution/user-execution.md)|The user opens a disk image file which invisibly installs its components. [[1]](#1)| +|[Defense Evasion::Self Deletion (F0007)](../defense-evasion/self-deletion.md)|The malware will monitor if a specific file gets deleted and then will delete itself. [[1]](#1)| |[Privilege Escalation::Install Certificate (E1608)](../privilege-escalation/install-certificate.md)|The malware installs a certificate. [[1]](#1)| -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|The malware installs a script to inject JavaScript script and modify web traffic. [[1]](#1)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|The malware installs a script to inject a JavaScript script and modify web traffic. [[1]](#1)| ## MBC Behaviors @@ -51,7 +52,7 @@ Adware that intercepts encrypted web traffic to inject ads. |Name|Use| |---|---| |[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)| The malware receives data from the C2 server. [[1]](#1)| -|[Impact::Manipulate Network Traffic (B0019)](../impact/manipulate-network-traffic.md)|Intercepts encrypted web traffic to inject adds. [[1]](#1)| +|[Impact::Manipulate Network Traffic (B0019)](../impact/manipulate-network-traffic.md)|SearchAwesome intercepts encrypted web traffic to inject ads. [[1]](#1)| |[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|The malware installs an open-source program called mitmproxy. [[1]](#1)| ## Indicators of Compromise @@ -62,9 +63,6 @@ Adware that intercepts encrypted web traffic to inject ads. - ~/Library/SPI/ - ~/.mitmproxy/ -SHA256 Hashes -- Unavailable - ## References diff --git a/xample-malware/shamoon.md b/xample-malware/shamoon.md index 28834a3..9a8e03c 100644 --- a/xample-malware/shamoon.md +++ b/xample-malware/shamoon.md @@ -1,7 +1,7 @@
IDX0017X0030
Aliases
- + @@ -24,56 +24,59 @@ # Shamoon -Data wiping malware. +Shamoon is a data wiping malware. ## ATT&CK Techniques |Name|Use| |---|---| -|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057)|Enumerate processes (This capa rule had 1 match) [[5]](#5) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Link many functions at runtime (This capa rule had 1 match) [[5]](#5) | -|[Execution::System Services::Service Execution (T1569.002)](https://attack.mitre.org/techniques/T1569/002)|Create service (This capa rule had 1 match) [[5]](#5) | -|[Persistence::Create or Modify System Process::Windows Service (T1543.003)](https://attack.mitre.org/techniques/T1543/003)|Start service (This capa rule had 1 match) [[5]](#5) | +|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057)|Shamoon enumerates processes. [[5]](#5)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Shamoon links many functions at runtime. [[5]](#5)| +|[Execution::System Services::Service Execution (T1569.002)](https://attack.mitre.org/techniques/T1569/002)|Shamoon creates services. [[5]](#5)| +|[Persistence::Create or Modify System Process::Windows Service (T1543.003)](https://attack.mitre.org/techniques/T1543/003)|Shamoon starts services. [[5]](#5)| See ATT&CK: [Shamoon - Techniques Used](https://attack.mitre.org/software/S0140/). + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Impact::Data Destruction (E1485)](../impact/data-destruction.md)|A 2018 variant includes a component that erases files and then wipes the master boot record, preventing file recovery [[1]](#1) | -|[Persistence::Modify Existing Service (F0011)](../persistence/modify-existing-service.md)|Shamoon enables the RemoteRegistry service to allow remote registry modification [[2]](#2) | -|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|Disables remote user account control by enabling the registry key LocalAccountTokenFilterPolicy [[2]](#2) | -|[Defense Evasion::Hidden Files and Directories::Timestamp (F0005.004)](../defense-evasion/hidden-files-and-directories.md)|Modifies target files' time to August 2012 as an antiforensic trick [[2]](#2) | -|[Defense Evasion::Hijack Execution Flow::Abuse Windows Function Calls (F0015.006)](../defense-evasion/hijack-execution-flow.md)|Escalates privilege by impersonating the token. First uses LogonUser and ImpersonateLoggedOnUser, then ImpersonateNamedPipeClient. [[2]](#2) | -|[Impact::Disk Wipe (F0014)](../impact/disk-wipe.md)|An overwrite component will overwrite the MBR so that the compromised computer can no longer start [[4]](#4) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|The wiper component of Shamoon creates a service to run the driver with the command: sc create hdv_725x type= kernel start= demand binpath= WINDOWS\hdv_725x.sys 2>&1 >nul and sends an additional reboot command after completion [[2]](#2) | -|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|Creates a folder on remote computers and then copies its executables (Shamoon and Filerase) into that directory [[3]](#3) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 1 match) [[5]](#5) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Get common file path (This capa rule had 1 match) [[5]](#5) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Get hostname (This capa rule had 1 match) [[5]](#5) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Accept command line arguments (This capa rule had 1 match) [[5]](#5) | +|[Impact::Data Destruction (E1485)](../impact/data-destruction.md)|A 2018 variant includes a component that erases files and then wipes the Master Boot Record (MBR), preventing file recovery. [[1]](#1)| +|[Persistence::Modify Existing Service (F0011)](../persistence/modify-existing-service.md)|Shamoon enables the RemoteRegistry service to allow remote registry modification. [[2]](#2)| +|[Defense Evasion::Modify Registry (E1112)](../defense-evasion/modify-registry.md)|Shamoon disables remote user account control by enabling the registry key LocalAccountTokenFilterPolicy. [[2]](#2)| +|[Defense Evasion::Hidden Files and Directories::Timestamp (F0005.004)](../defense-evasion/hidden-files-and-directories.md)|Shamoon modifies target files' time to August 2012 as an antiforensic trick. [[2]](#2)| +|[Defense Evasion::Hijack Execution Flow::Abuse Windows Function Calls (F0015.006)](../defense-evasion/hijack-execution-flow.md)|Malware escalates privileges by impersonating the token through using LogonUser and ImpersonateLoggedOnUser then ImpersonateNamedPipeClient. [[2]](#2)| +|[Impact::Disk Wipe (F0014)](../impact/disk-wipe.md)|An overwrite component will overwrite the MBR so that the compromised computer can no longer start. [[4]](#4)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|The wiper component of Shamoon creates a service to run the driver with the command: sc create hdv_725x type= kernel start= demand binpath= WINDOWS\hdv_725x.sys 2>&1 >nul and sends an additional reboot command after completion. [[2]](#2)| +|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|Shamoon creates a folder on remote computers and then copies its executables (Shamoon and Filerase) into that directory. [[3]](#3)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Shamoon encodes data using XOR. [[5]](#5)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Shamoon gets a common file path. [[5]](#5)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Shamoon gets the hostname. [[5]](#5)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Shamoon accepts command line arguments. [[5]](#5)| + ## MBC Behaviors |Name|Use| |---|---| -|[Anti-Behavioral Analysis::Conditional Execution::Runs as Service (B0025.007)](../execution/conditional-execution.md)|Run as service (This capa rule had 1 match) [[5]](#5) | -|[Communication::DNS Communication::Resolve (C0011.001)](../micro-behaviors/communication/dns-communication.md)|Resolve DNS (This capa rule had 1 match) [[5]](#5) | -|[Communication::Socket Communication::Initialize Winsock Library (C0001.009)](../micro-behaviors/communication/socket-communication.md)|Initialize Winsock library (This capa rule had 1 match) [[5]](#5) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 1 match) [[5]](#5) | -|[File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|Copy file (This capa rule had 2 matches) [[5]](#5) | -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 6 matches) [[5]](#5) | -|[File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|Move file (This capa rule had 2 matches) [[5]](#5) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 1 match) [[5]](#5) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Write file on Windows (This capa rule had 1 match) [[5]](#5) | -|[Operating System::Registry::Delete Registry Value (C0036.007)](../micro-behaviors/operating-system/registry.md)|Delete registry value (This capa rule had 1 match) [[5]](#5) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 1 match) [[5]](#5) | -|[Process::Allocate Thread Local Storage (C0040)](../micro-behaviors/process/allocate-thread-local-storage.md)|Allocate thread local storage (This capa rule had 1 match) [[5]](#5) | -|[Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Create process on Windows (This capa rule had 2 matches) [[5]](#5) | -|[Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|Create thread (This capa rule had 2 matches) [[5]](#5) | -|[Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Terminate process (This capa rule had 1 match) [[5]](#5) | +|[Execution::Conditional Execution::Runs as Service (B0025.007)](../execution/conditional-execution.md)|Shamoon runs as a service. [[5]](#5)| +|[Micro-Behaviors::Communication::DNS Communication::Resolve (C0011.001)](../micro-behaviors/communication/dns-communication.md)|Shamoon resolves DNS. [[5]](#5)| +|[Micro-Behaviors::Communication::Socket Communication::Initialize Winsock Library (C0001.009)](../micro-behaviors/communication/socket-communication.md)|Shamoon initializes a Winsock library. [[5]](#5)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Shamoon encodes data using XOR. [[5]](#5)| +|[Micro-Behaviors::File System::Copy File (C0045)](../micro-behaviors/file-system/copy-file.md)|Shamoon copies files. [[5]](#5)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Shamoon deletes files. [[5]](#5)| +|[Micro-Behaviors::File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|Shamoon moves files. [[5]](#5)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Shamoon reads files on Windows. [[5]](#5)| +|[Micro-Behaviors::File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Shamoon writes files on Windows. [[5]](#5)| +|[Micro-Behaviors::Operating System::Registry::Delete Registry Value (C0036.007)](../micro-behaviors/operating-system/registry.md)|Shamoon deletes registry values. [[5]](#5)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Shamoon queries or enumerates registry values. [[5]](#5)| +|[Micro-Behaviors::Process::Allocate Thread Local Storage (C0040)](../micro-behaviors/process/allocate-thread-local-storage.md)|Shamoon allocates thread local storage. [[5]](#5)| +|[Micro-Behaviors::Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Shamoon creates a process on Windows. [[5]](#5)| +|[Micro-Behaviors::Process::Create Thread (C0038)](../micro-behaviors/process/create-thread.md)|Shamoon creates a thread. [[5]](#5)| +|[Micro-Behaviors::Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Shamoon terminates processes. [[5]](#5)| + ## Indicators of Compromise @@ -81,6 +84,7 @@ SHA256 Hashes - c617120895646f73bc880c0aca18990deda3db9be03f6b3564013e26dedfa3f9 - 4f02a9fcd2deb3936ede8ff009bd08662bdb1f365c0f4a78b3757a98c2f40400 + ## References [1] https://www.darkreading.com/attacks-breaches/disk-wiping-shamoon-malware-resurfaces-with-file-erasing-malware-in-tow diff --git a/xample-malware/stuxnet.md b/xample-malware/stuxnet.md index c13e615..eff2804 100644 --- a/xample-malware/stuxnet.md +++ b/xample-malware/stuxnet.md @@ -1,7 +1,7 @@
IDX0018X0031
Aliases
- + @@ -24,14 +24,14 @@ # Stuxnet -A malicious worm targeting SCADA systems. +Stuxnet is a malicious worm targeting SCADA systems. ## ATT&CK Techniques |Name|Use| |---|---| -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Parse PE header (This capa rule had 2 matches) [[2]](#2) | +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Stuxnet parses PE headers. [[2]](#2)| See ATT&CK: [Stuxnet - Techniques Used](https://attack.mitre.org/software/S0603/). @@ -39,32 +39,35 @@ See ATT&CK: [Stuxnet - Techniques Used](https://attack.mitre.org/software/S0603/ |Name|Use| |---|---| -|[Defense Evasion::Hijack Execution Flow::Import Address Table Hooking (F0015.003)](../defense-evasion/hijack-execution-flow.md)|Stuxnet hooks ntdll.dll to monitor for requests to load specially crafted file names which are mapped to a location specified by Stuxnet. [[1]](#1) | -|[Defense Evasion::Process Injection::Dynamic-link Library Injection (E1055.001)](../defense-evasion/process-injection.md)|Stuxnet injects the entire DLL into another process and then just calls the particular export [[1]](#1) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Gathers information (OS version, workgroup status, computer name, domain/workgroup name, file name of infected project file) about each computer in the net to spread itself [[1]](#1) | -|[Anti-Static Analysis::Obfuscated Files or Information::Encoding (E1027.m01)](../defense-evasion/obfuscated-files-or-information.md)|The configuration data block is encoded with a NOT XOR 0xFF operation [[1]](#1) | -|[Defense Evasion::Rootkit::Kernel Mode Rootkit (E1014.m17)](../defense-evasion/rootkit.md)|Stuxnet registers custom resource drives signed with a legitimate Realtek digital certificate [[1]](#1) | -|[Defense Evasion::Process Injection::Injection and Persistence via Registry Modification (E1055.m05)](../defense-evasion/process-injection.md)|The driver Stuxnet uses for persistence Mrxcls.sys is registered as a boot start service creating the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxCIs\"ImagePath" = "%System%\drivers\mrxcls.sys" [[1]](#1) | -|[Exfiltration::Archive Collected Data::Encoding - Custom Encoding (E1560.m04)](../exfiltration/archive-collected-data.md)|Exfiltrated payloads are XORed with a static 31-byte long byte string found inside Stuxnet and hexified in order to be passed on as an ASCII data parameter in an HTTP request to the C2 servers [[1]](#1) | -|[Defense Evasion::Hide Artifacts (E1564)](../defense-evasion/hide-artifacts.md)|Stuxnet intercepts IRP requests (reads, writes) to devices (NFTS, FAT, CD-ROM). It monitors directory control IRPs, in particular directory query notifications such that when an application requests the list of files, it returns a Stuxnet-specified subset of the true items. These filters hide the files used by Stuxnet to spread through removalbe drives [[1]](#1) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Stuxnet will store and execute SQL code that will extract and execute Stuxnet from the saved CAB file using xp_cmdshell [[1]](#1) | -|[Defense Evasion::Hijack Execution Flow::Procedure Hooking (F0015.007)](../defense-evasion/hijack-execution-flow.md)|WTR4141.tmp hooks APIs from kernel32.dll and Ntdll.dll and replaces the original code for these functions with code that checks for files with properties pertaining to Stuxnet files. If a request is made to list a file with the specified properties, the response from these APIs is altered to state that the file does not exist, thereby hiding all files with these properties. [[1]](#1) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 3 matches) [[2]](#2) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Check OS version (This capa rule had 1 match) [[2]](#2) | +|[Defense Evasion::Hijack Execution Flow::Import Address Table Hooking (F0015.003)](../defense-evasion/hijack-execution-flow.md)|Stuxnet hooks ntdll.dll to monitor for requests to load specially crafted file names, which are mapped to a location specified by Stuxnet. [[1]](#1)| +|[Defense Evasion::Process Injection::Dynamic-link Library Injection (E1055.001)](../defense-evasion/process-injection.md)|Stuxnet injects the entire DLL into another process and then calls the particular export. [[1]](#1)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Stuxnet gathers information (OS version, workgroup status, computer name, domain/workgroup name, file name of infected project file) about each computer in the network to spread itself. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information::Encoding (E1027.m01)](../defense-evasion/obfuscated-files-or-information.md)|The configuration data block is encoded with a NOT XOR 0xFF operation. [[1]](#1)| +|[Defense Evasion::Rootkit::Kernel Mode Rootkit (E1014.m16)](../defense-evasion/rootkit.md)|Stuxnet registers custom resource drives signed with a legitimate Realtek digital certificate. [[1]](#1)| +|[Defense Evasion::Process Injection::Injection and Persistence via Registry Modification (E1055.m02)](../defense-evasion/process-injection.md)|Stuxnet uses Mrxcls.sys driver for persistence. It is registered as a boot start service by creating the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MRxCIs\"ImagePath" = "%System%\drivers\mrxcls.sys". [[1]](#1)| +|[Exfiltration::Archive Collected Data::Encoding - Custom Encoding (E1560.m04)](../exfiltration/archive-collected-data.md)|Stuxnet exfiltrated payloads are XORed with a static 31-byte long byte string found inside Stuxnet and hexified in order to be passed on as an ASCII data parameter in an HTTP request to the C2 servers. [[1]](#1)| +|[Defense Evasion::Hide Artifacts (E1564)](../defense-evasion/hide-artifacts.md)|Stuxnet intercepts IRP requests (reads, writes) to devices (NFTS, FAT, CD-ROM). It monitors directory control IRPs, in particular directory query notifications, such that when an application requests the list of files, it returns a Stuxnet-specified subset of the true items. These filters hide the files used by Stuxnet to spread through removable drives. [[1]](#1)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Stuxnet will store and execute SQL code that will extract and execute Stuxnet from the saved CAB file using xp_cmdshell. [[1]](#1)| +|[Defense Evasion::Hijack Execution Flow::Procedure Hooking (F0015.007)](../defense-evasion/hijack-execution-flow.md)|WTR4141.tmp hooks APIs from kernel32.dll and ntdll.dll and replaces the original code for these functions with code that checks for files with properties pertaining to Stuxnet files. If a request is made to list a file with the specified properties, the response from these APIs is altered to state that the file does not exist, thereby hiding all files with these properties. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Stuxnet encodes data using XOR. [[2]](#2)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Stuxnet checks OS version. [[2]](#2)| + ## MBC Behaviors |Name|Use| |---|---| -|[Impact::Destroy Hardware (B0017)](../impact/destroy-hardware.md)|Stuxnet made the centrifuges at Iran's nuclear plant spin dangerously fast for 15 minutes, before returning to normal speed. About a month later, it slowed the centrifuges down for 50 minutes. This was repeated for several months, and over the strain destroyed the machines [[1]](#1)| -|[Micro-Objective::Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Creates global mutexes signal that rootkit installation has occurred successfully [[1]](#1)| -|[Micro-Objective::Process::Create Process::Create Process via WMI (C0017.002)](../micro-behaviors/process/create-process.md)|Stuxnet will use WMI operations with the explorere.exe token in order to copy itself and exscute on the remote share [[1]](#1)| -|[Execution::Conditional Execution::Host Fingerprint Check (B0025.004)](../execution/conditional-execution.md)|Stuxnet checks for specific operating systems on 32-bit machines, registry keys, and dates to profile a potential target machine before execution. If the conditions are not met to be considered a viable target, it will exit execution [[1]](#1)| -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 3 matches) [[2]](#2)| -|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Enumerate PE sections (This capa rule had 1 match) [[2]](#2)| -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 1 match) [[2]](#2)| -|[Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Allocate RWX memory (This capa rule had 1 match) [[2]](#2)| -|[Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Terminate process (This capa rule had 1 match) [[2]](#2)| +|[Impact::Destroy Hardware (B0017)](../impact/destroy-hardware.md)|Stuxnet made the centrifuges at Iran's nuclear plant spin dangerously fast for 15 minutes, before returning to normal speed. About a month later, it slowed the centrifuges down for 50 minutes. This was repeated for several months, and over time the strain destroyed the machines. [[1]](#1) [[3]](#3)| +|[Micro-behaviors::Process::Create Mutex (C0042)](../micro-behaviors/process/create-mutex.md)|Malware creates global mutexes that signal rootkit installation has occurred successfully. [[1]](#1)| +|[Micro-behaviors::Process::Create Process::Create Process via WMI (C0017.002)](../micro-behaviors/process/create-process.md)|Stuxnet will use WMI operations with the explorer.exe token in order to copy itself and execute on the remote share. [[1]](#1)| +|[Execution::Conditional Execution::Host Fingerprint Check (B0025.004)](../execution/conditional-execution.md)|Stuxnet checks for specific operating systems on 32-bit machines, registry keys, and dates to profile a potential target machine before execution. If the conditions are not met to be considered a viable target, it will exit execution. [[1]](#1)| +|[Anti-Behavioral Analysis::Emulator Detection (B0004)](../anti-behavioral-analysis/emulator-detection.md)|Stuxnet checks for specific operating systems on 32-bit machines, registry keys, and dates to profile a potential target machine before execution. If the conditions are not met to be considered a viable target, it will exit execution. [[1]](#1)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Stuxnet encodes data using XOR. [[2]](#2)| +|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Stuxnet enumerates PE sections. [[2]](#2)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Stuxnet deletes files. [[2]](#2)| +|[Micro-Behaviors::Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Stuxnet allocates RWX memory. [[2]](#2)| +|[Micro-Behaviors::Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Stuxnet terminates processes. [[2]](#2)| + ## Indicators of Compromise @@ -78,3 +81,4 @@ SHA256 Hashes [2] capa v4.0, analyzed at MITRE on 10/12/2022 +[3] https://www.bbc.com/timelines/zc6fbk7 \ No newline at end of file diff --git a/xample-malware/synful-knock.md b/xample-malware/synful-knock.md index 5c55fb7..8fe10b1 100644 --- a/xample-malware/synful-knock.md +++ b/xample-malware/synful-knock.md @@ -2,7 +2,7 @@
IDX0019X0032
Aliases
- + @@ -25,28 +25,25 @@ # SYNful Knock -A modification of the router's firmware images used to maintain persistence. [[1]](#1) +SYNful Knock is a modification of the router's firmware images used to maintain persistence. [[1]](#1) + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Persistence::Component Firmware::Router Firmware (F0009.001)](../persistence/component-firmware.md)|Modification of the router's firmware image that can be used to maintain persistence within a victim's network [[1]](#1)| -|[Defense Evasion::Hijack Execution Flow (F0015)](../defense-evasion/hijack-execution-flow.md)|Hooks IOS functions to call and initialize the malware [[1]](#1)| +|[Persistence::Component Firmware::Router Firmware (F0009.001)](../persistence/component-firmware.md)|SYNful Knock is a stealthy modification of the router's firmware image that can be used to maintain persistence within a victim's network. [[1]](#1)| +|[Defense Evasion::Hijack Execution Flow (F0015)](../defense-evasion/hijack-execution-flow.md)|SYNful Knock hooks iOS functions to call and initialize the malware. [[1]](#1)| ## MBC Behaviors |Name|Use| |---|---| -|[Micro-Objective::Memory::Change Memory Protection (C0008)](../micro-behaviors/memory/change-memory-protection.md)|Modifies the translation lookaside buffer (TLB) Read/Write attributes [[1]](#1)| -|[Micro-objective::Communication::Socket Communication::Send TCP Data (C0001.014)](../micro-behaviors/communication/socket-communication.md)|To initiate communication with the C2 server, a uniquely crafted TCP SYN packet is sent to port 80 of the "implanted" router [[1]](#1)| -|[Defense Evasion::Alternative Installation Location::Fileless Malware (B0027.001)](../defense-evasion/alternative-installation-location.md)|100 memory-resident modules can be installed [[1]](#1)| +|[Micro-behaviors::Memory::Change Memory Protection (C0008)](../micro-behaviors/memory/change-memory-protection.md)|SYNful Knock modifies the translation lookaside buffer (TLB) Read/Write attributes. [[1]](#1)| +|[Micro-behaviors::Communication::Socket Communication::Send TCP Data (C0001.014)](../micro-behaviors/communication/socket-communication.md)|To initiate communication with the C2 server, a uniquely crafted TCP SYN packet is sent to port 80 of the "implanted" router. [[1]](#1)| +|[Defense Evasion::Alternative Installation Location::Fileless Malware (B0027.001)](../defense-evasion/alternative-installation-location.md)|100 memory-resident modules can be installed. [[1]](#1)| -## Indicators of Compromise - -SHA256 Hashes -- Unavailable ## References diff --git a/xample-malware/teardrop.md b/xample-malware/teardrop.md new file mode 100644 index 0000000..69aaed7 --- /dev/null +++ b/xample-malware/teardrop.md @@ -0,0 +1,59 @@ + +
IDX0020X0033
Aliases
+ + + + + + + + + + + + + + + + + + + + +
IDX0034
AliasesNone
PlatformsWindows
Year2018
Associated ATT&CK SoftwareTEARDROP
+ + +# TEARDROP + +TEARDROP is a memory-only loader that is associated with the Solarwinds supply chain compromise. + + +## ATT&CK Techniques + +See ATT&CK: [TEARDROP - Techniques Used](https://attack.mitre.org/software/S0560/). + + +## Enhanced ATT&CK Techniques + +|Name|Use| +|---|---| +|[Defense Evasion::Obfuscated Files or Information::Encryption-Standard Algorithm (E1027.m05)](../defense-evasion/obfuscated-files-or-information.md)|Malware decrypts an embedded code buffer using an XOR-based stream cipher. [[1]](#1)| +|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|Malware executes the decrypted, embedded code buffer, which is a Cobalt Strike Remote Access Tool (RAT). [[1]](#1)| + + + +## MBC Behaviors + +|Name|Use| +|---|---| +|[Anti-Behavioral Analysis::Capture Evasion::Memory-only Payload (B0036.001)](../anti-behavioral-analysis/capture-evasion.md)|Malware loads its payload into memory. [[1]](#1)| + + +## Indicators of Compromise + + +## References + +[1] https://www.cisa.gov/uscert/ncas/analysis-reports/ar21-039b/ + + diff --git a/xample-malware/terminator.md b/xample-malware/terminator.md index e3fb038..d9f7273 100644 --- a/xample-malware/terminator.md +++ b/xample-malware/terminator.md @@ -2,7 +2,7 @@ - + @@ -25,30 +25,33 @@ # Terminator -A remote access tool (RAT). +Terminator is a remote access tool (RAT). ## ATT&CK Techniques |Name|Use| |---|---| -|[Defense Evasion::Virtualization/Sandbox Evasion::User Activity Based Checks (T1497)](https://attack.mitre.org/techniques/T1497/)|The Terminator rat evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[2]](#2)| +|[Defense Evasion::Virtualization/Sandbox Evasion::User Activity Based Checks (T1497)](https://attack.mitre.org/techniques/T1497/)|The Terminator RAT evades sandboxes by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[2]](#2)| + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Defense Evasion::Self Deletion (F0007.001)](../defense-evasion/self-deletion.md)|Evades sandboxes by terminating and removing itself (DW20.exe) after installation. [[2]](#2)| -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|Sets "2019" as Windows' startup folder by modifying a registry value. [[1]](#1)| -|[Execution::User Execution (E1204)](../execution/user-execution.md)|The malware relies on user interaction to execute [[2]](#2)| +|[Defense Evasion::Self Deletion (F0007.001)](../defense-evasion/self-deletion.md)|The RAT evades sandboxes by terminating and removing itself (DW20.exe) after installation. [[2]](#2)| +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|The RAT sets "2019" as a Windows' startup folder by modifying a registry value. [[1]](#1)| +|[Execution::User Execution (E1204)](../execution/user-execution.md)|The malware relies on user interaction to execute. [[2]](#2)| ## MBC Behaviors |Name|Use| |---|---| -|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|The malware sends data to C2 [[2]](#2)| -|[Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed Execution (B0003.003)](../anti-behavioral-analysis/dynamic-analysis-evasion.md)|The Terminator rat evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[1]](#1)| +|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|The malware sends data to the C2. [[2]](#2)| +|[Anti-Behavioral Analysis::Dynamic Analysis Evasion::Delayed Execution (B0003.003)](../anti-behavioral-analysis/dynamic-analysis-evasion.md)|The Terminator RAT evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[1]](#1)| +|[Anti-Behavioral Analysis::Sandbox Detection (B0007)](../anti-behavioral-analysis/sandbox-detection.md)|The Terminator RAT evades a sandbox by not executing until after a reboot. Most sandboxes don't reboot during an analysis. [[1]](#1)| + ## Indicators of Compromise diff --git a/xample-malware/trickbot.md b/xample-malware/trickbot.md index fd41ad9..5f4c284 100644 --- a/xample-malware/trickbot.md +++ b/xample-malware/trickbot.md @@ -1,7 +1,7 @@
IDX0021X0035
Aliases
- + @@ -24,14 +24,14 @@ # TrickBot -Trojan spyware program that has mainly been used for targeting banking sites. TrickBot is written in the C++ programming language. +TrickBot is a trojan spyware program that has mainly been used for targeting banking sites. TrickBot is written in the C++ programming language. ## ATT&CK Techniques |Name|Use| |---|---| -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Parse PE header (This capa rule had 2 matches) [[7]](#7) | +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|TrickBot parses PE headers. [[7]](#7)| See ATT&CK: [TrickBot - Techniques Used](https://attack.mitre.org/software/S0266/). @@ -39,36 +39,40 @@ See ATT&CK: [TrickBot - Techniques Used](https://attack.mitre.org/software/S0266 |Name|Use| |---|---| -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Collects local files with specified file extensions and information from the victim's machine [[1]](#1) | -|[Anti-Static Analysis::Software Packing (F0001)](../anti-static-analysis/software-packing.md)|Has a custom packer to obfuscate itself [[1]](#1) | -|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|Injects itself into svchost.exe [[2]](#2) | -|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|Has an auto-start service that allows it to run whenever the machine boots [[3]](#3) | -|[Defense Evasion::Indicator Blocking (F0006)](../defense-evasion/indicator-blocking.md)|Terminates the following anti-malware services: Window Defender, MBamService (Malwarebytes), SAVService (Sophos AV) [[3]](#3) | -|[Exfiltration::Archive Collected Data::Encryption (E1560.m02)](../exfiltration/archive-collected-data.md)|Uses a custom crypter leveraging Microsoft's CryptoAPI to encrypt C2 traffic. C2 update responses seem to have been digitally signed using bcrypt [[4]](#4) | -|[Defense Evasion::Bootkit (F0013)](../defense-evasion/bootkit.md)|Can implement malicious code into firmware, allowing read, write, and/or erasure of the UEFI/BIOS firmware [[5]](#5) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Can collect information about the compter, resources, services, installed programs, firmware, and operating system version [[1]](#1) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 2 matches) [[7]](#7) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Accept command line arguments (This capa rule had 1 match) [[7]](#7) | +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|The malware collects machine information and local files with specified file extensions. [[1]](#1)| +|[Anti-Static Analysis::Software Packing (F0001)](../anti-static-analysis/software-packing.md)|The malware has a custom packer to obfuscate itself. [[1]](#1)| +|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|The malware injects itself into svchost.exe. [[2]](#2)| +|[Persistence::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|The malware has an auto-start service that allows it to run whenever the machine boots. [[3]](#3)| +|[Defense Evasion::Disable or Evade Security Tool (F0004)](../defense-evasion/disable-or-evade-security-tools.md)|The malware terminates the following anti-malware services: Window Defender, MBamService (Malwarebytes), SAVService (Sophos AV). [[3]](#3)| +|[Exfiltration::Archive Collected Data::Encryption (E1560.m02)](../exfiltration/archive-collected-data.md)|The malware uses a custom crypter leveraging Microsoft's CryptoAPI to encrypt C2 traffic. C2 update responses seem to have been digitally signed using bcrypt. [[4]](#4)| +|[Defense Evasion::Bootkit (F0013)](../defense-evasion/bootkit.md)|The malware can implement malicious code into firmware, allowing read, write, and/or erasure of the UEFI/BIOS firmware. [[5]](#5)| +|[Lateral Movement::Supply Chain Compromise (E1195)](../lateral-movement/supply-chain-compromise.md)|TrickBot comes with a signed downloader component. [[5]](#5)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|The malware collects information about the computer, resources, services, installed programs, firmware, and operating system versions. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|TrickBot encodes data using XOR. [[7]](#7)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|TrickBot accepts command line arguments. [[7]](#7)| + ## MBC Behaviors |Name|Use| |---|---| -|[Execution::Remote Commands (B0011)](../execution/remote-commands.md)|Receives various commands from c2 server. [[2]](#2) | -|[Micro-Objective::Cryptography::Encrypt Data::AES (C0027.001)](../micro-behaviors/cryptography/encrypt-data.md)|Uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files [[1]](#1) | -|[Anti-Behavioral Analysis::Dynamic Analysis Evasion (B0003.012)](../anti-behavioral-analysis/dynamic-analysis-evasion.md)|Uses numerous printf loops to delay the execution process and overload the sandbox with junk data (API Hammering) [[6]](#6) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 2 matches) [[7]](#7) | -|[Discovery::Code Discovery::Inspect Section Memory Permissions (B0046.002)](../discovery/code-discovery.md)|Inspect section memory permissions (This capa rule had 2 matches) [[7]](#7) | -|[Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|Allocate RWX memory (This capa rule had 7 matches) [[7]](#7) | -|[Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Create process on Windows (This capa rule had 1 match) [[7]](#7) | -|[Process::Create Process::Create Suspended Process (C0017.003)](../micro-behaviors/process/create-process.md)|Create process suspended (This capa rule had 1 match) [[7]](#7) | -|[Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Terminate process (This capa rule had 1 match) [[7]](#7) | -|[Impact::Spamming (B0039)](../impact/spamming.md)|TrickBot was observed infecting computers to steal email passwords and address books to spread malicious emails [[8]](#8)| +|[Execution::Remote Commands (B0011)](../execution/remote-commands.md)|The malware receives various commands from the C2 server. [[2]](#2)| +|[Micro-behaviors::Cryptography::Encrypt Data::AES (C0027.001)](../micro-behaviors/cryptography/encrypt-data.md)|The malware uses an AES CBC (256 bits) encryption algorithm for its loader and configuration files. [[1]](#1)| +|[Anti-Behavioral Analysis::Dynamic Analysis Evasion (B0003.012)](../anti-behavioral-analysis/dynamic-analysis-evasion.md)|The malware uses numerous printf loops to delay the execution process and overload the sandbox with junk data (API Hammering). [[6]](#6)| +|[Impact::Spamming (B0039)](../impact/spamming.md)|In July 2019, TrickBot was observed infecting computers to steal email passwords and address books to spread malicious emails. [[8]](#8)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|TrickBot encodes data using XOR. [[7]](#7)| +|[Discovery::Code Discovery::Inspect Section Memory Permissions (B0046.002)](../discovery/code-discovery.md)|TrickBot inspects section memory permissions. [[7]](#7)| +|[Micro-Behaviors::Memory::Allocate Memory (C0007)](../micro-behaviors/memory/allocate-memory.md)|TrickBot allocates RWX memory. [[7]](#7)| +|[Micro-Behaviors::Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|TrickBot creates a process on Windows. [[7]](#7)| +|[Micro-Behaviors::Process::Create Process::Create Suspended Process (C0017.003)](../micro-behaviors/process/create-process.md)|TrickBot creates a suspended process. [[7]](#7)| +|[Micro-Behaviors::Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|TrickBot terminates processes. [[7]](#7)| + ## Indicators of Compromise SHA256 Hashes - a162bb9219a09b302b90bc6f908e117e3fb2c722560336d378fd76a8f22f78f8 + MD5 Hashes - 28661ea73413822c3b5b7de1bef0b246 - 218613f0f1d2780f08e754be9e6f8c64 @@ -76,6 +80,7 @@ MD5 Hashes - 719578c91b4985d1f955f6adb688314f - 132c4338cdc46a0a286abf574d68e2e0 - e8e7b0a8f274cad7bdaedd5a91b5164d + Yara Rules - rule MALW_trickbot_bankBot : Trojan { meta: author = "Marc Salinas @Bondey_m" description = "Detects Trickbot Banking Trojan" strings: $str_trick_01 = "moduleconfig" $str_trick_02 = "Start" $str_trick_03 = "Control" $str_trick_04 = "FreeBuffer" $str_trick_05 = "Release" condition: all of ($str_trick_*) } - rule MALW_systeminfo_trickbot_module : Trojan { meta: author = "Marc Salinas @Bondey_m" description = "Detects systeminfo module from Trickbot Trojan" strings: $str_systeminf_01 = "" $str_systeminf_02 = "" $str_systeminf_03 = "" $str_systeminf_04 = "GetSystemInfo.pdb" $str_systeminf_05 = "" $str_systeminf_06 = "" condition: all of ($str_ systeminf_*) } @@ -99,3 +104,4 @@ Yara Rules [7] capa v4.0, analyzed at MITRE on 10/12/2022 [8] https://techcrunch.com/2019/07/12/trickbot-spam-millions-emails/ + diff --git a/xample-malware/up007.md b/xample-malware/up007.md index c68cf81..46f0e23 100644 --- a/xample-malware/up007.md +++ b/xample-malware/up007.md @@ -1,7 +1,7 @@
IDX0025X0036
Aliases
- + @@ -22,64 +22,67 @@
IDX0033X0037
Aliases
-# UP007 Malware Family +# UP007 -Malware utilized in an espionage campaign targeting Hong Kong democracy activists. [[1]](#1) +UP007 is a dropper used in an espionage campaign targeting Hong Kong democracy activists. [[1]](#1) ## ATT&CK Techniques |Name|Use| |---|---| -|[Initial Access::Phishing::Spearphishing Link (T1566.002)](https://attack.mitre.org/techniques/T1566/002/)|The malware is sent to the victim via a link [[1]](#1) | -|[Defense Evasion::Deobfuscate/Decode Files or Information (T1140)](https://attack.mitre.org/techniques/T1140/)|The malware "dropper will decode and write the files stored in encoded form" [[1]](#1) | -|[Discovery::Query Registry (T1012)](https://attack.mitre.org/techniques/T1012/)|The malware queries registry to detect AV [[1]](#1) query or enumerate registry value (This capa rule had 2 matches) [[2]](#2) | -|[Defense Evasion::Hijack Execution Flow::DLL Side-Loading (T1574.002)](https://attack.mitre.org/techniques/T1574/002/)|The malware loads multiple DLLs into memory [[1]](#1) | -|[Command and Control::Application Layer Protocol::Web Protocols (T1071.001)](https://attack.mitre.org/techniques/T1071/001/)|The malware communicates to the C2 server using HTTP [[1]](#1) | -|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|Set file attributes (This capa rule had 4 matches) [[2]](#2) | -|[Defense Evasion::Hide Artifacts::Hidden Window (T1564.003)](https://attack.mitre.org/techniques/T1564/003)|Hide graphical window (This capa rule had 2 matches) [[2]](#2) | -|[Discovery::Application Window Discovery (T1010)](https://attack.mitre.org/techniques/T1010)|Find graphical window (This capa rule had 1 match) [[2]](#2) | -|[Discovery::System Location Discovery (T1614)](https://attack.mitre.org/techniques/T1614)|Get geographical location (This capa rule had 1 match) [[2]](#2) | -|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|Link function at runtime on Windows (This capa rule had 2 matches) [[2]](#2) | -|[Privilege Escalation::Access Token Manipulation (T1134)](https://attack.mitre.org/techniques/T1134)|Modify access privileges (This capa rule had 1 match) [[2]](#2) | +|[Initial Access::Phishing::Spearphishing Link (T1566.002)](https://attack.mitre.org/techniques/T1566/002/)|The malware is sent to the victim via a link. [[1]](#1)| +|[Defense Evasion::Deobfuscate/Decode Files or Information (T1140)](https://attack.mitre.org/techniques/T1140/)|The dropper writes files in encoded form and decodes files. [[1]](#1)| +|[Discovery::Query Registry (T1012)](https://attack.mitre.org/techniques/T1012/)|The malware queries the registry to detect AVs and queries or enumerates registry values. [[1]](#1) [[2]](#2)| +|[Defense Evasion::Hijack Execution Flow::DLL Side-Loading (T1574.002)](https://attack.mitre.org/techniques/T1574/002/)|The malware loads multiple DLLs into memory. [[1]](#1)| +|[Command and Control::Ingress Tool Transfer (T1105)](https://attack.mitre.org/techniques/T1105/)|The malware downloads files from the C2. [[1]](#1)| +|[Command and Control::Application Layer Protocol::Web Protocols (T1071.001)](https://attack.mitre.org/techniques/T1071/001/)|The malware communicates to the C2 server using HTTP. [[1]](#1)| +|[Defense Evasion::File and Directory Permissions Modification (T1222)](https://attack.mitre.org/techniques/T1222)|UP007 sets file attributes. [[2]](#2)| +|[Defense Evasion::Hide Artifacts::Hidden Window (T1564.003)](https://attack.mitre.org/techniques/T1564/003)|UP007 hides a graphical window. [[2]](#2)| +|[Discovery::Application Window Discovery (T1010)](https://attack.mitre.org/techniques/T1010)|UP007 finds a graphical window. [[2]](#2)| +|[Discovery::System Location Discovery (T1614)](https://attack.mitre.org/techniques/T1614)|UP007 gets geographical locations. [[2]](#2)| +|[Execution::Shared Modules (T1129)](https://attack.mitre.org/techniques/T1129)|UP007 links functions at runtime on Windows. [[2]](#2)| +|[Privilege Escalation::Access Token Manipulation (T1134)](https://attack.mitre.org/techniques/T1134)|UP007 modifies access privileges. [[2]](#2)| + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|The malware downloads files from C2 [[1]](#1) | -|[Collection::Keylogging (F0002)](../collection/keylogging.md)|The malware logs keystrokes to a file [[1]](#1) | -|[Defense Evasion::Process Injection::Dynamic-link Library Injection (E1055)](../defense-evasion/process-injection.md)|The malware loads multiple DLLs into memory [[1]](#1) | -|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|Encode data using XOR (This capa rule had 13 matches) [[2]](#2) | -|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|Get graphical window text (This capa rule had 1 match) [[2]](#2) | -|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|Enumerate files on windows (This capa rule had 1 match) [[2]](#2) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Query environment variable (This capa rule had 1 match) [[2]](#2) | -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|Accept command line arguments (This capa rule had 1 match) [[2]](#2) | +|[Collection::Keylogging (F0002)](../collection/keylogging.md)|The malware logs keystrokes to a file. [[1]](#1)| +|[Defense Evasion::Process Injection::Dynamic-link Library Injection (E1055.001)](../defense-evasion/process-injection.md)|The malware loads multiple DLLs into memory. [[1]](#1)| +|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|The malware downloads files from the C2. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information::Encoding-Standard Algorithm (E1027.m02)](../defense-evasion/obfuscated-files-or-information.md)|UP007 encodes data using XOR. [[2]](#2)| +|[Discovery::Application Window Discovery::Window Text (E1010.m01)](../discovery/application-window-discovery.md)|UP007 gets graphical window text. [[2]](#2)| +|[Discovery::File and Directory Discovery (E1083)](../discovery/file-and-directory-discovery.md)|UP007 enumerates files on Windows. [[2]](#2)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|UP007 queries environment variables. [[2]](#2)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|UP007 accepts command line arguments. [[2]](#2)| ## MBC Behaviors |Name|Use| |---|---| -|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|The malware receives payloads [[1]](#1) | -|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|The malware sends harded HTTP headers disguised as Microsoft Update traffic [[1]](#1) | -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|The malware is a dropper that creates multiple files [[1]](#1) | -|[Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)](../anti-behavioral-analysis/debugger-detection.md)|Check for time delay via GetTickCount (This capa rule had 1 match) [[2]](#2) | -|[Cryptography::Cryptographic Hash::SHA1 (C0029.002)](../micro-behaviors/cryptography/cryptographic-hash.md)|Hash data using SHA1 (This capa rule had 1 match) [[2]](#2) | -|[Data::Checksum::CRC32 (C0032.001)](../micro-behaviors/data/checksum.md)|Hash data with CRC32 (This capa rule had 1 match) [[2]](#2) | -|[Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|Encode data using XOR (This capa rule had 13 matches) [[2]](#2) | -|[File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|Create directory (This capa rule had 1 match) [[2]](#2) | -|[File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|Delete file (This capa rule had 2 matches) [[2]](#2) | -|[File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|Get file attributes (This capa rule had 7 matches) [[2]](#2) | -|[File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|Move file (This capa rule had 2 matches) [[2]](#2) | -|[File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|Read file on Windows (This capa rule had 1 match) [[2]](#2) | -|[File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|Set file attributes (This capa rule had 4 matches) [[2]](#2) | -|[File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|Write file on Windows (This capa rule had 1 match) [[2]](#2) | -|[Operating System::Environment Variable::Set Variable (C0034.001)](../micro-behaviors/operating-system/environment-variable.md)|Set environment variable (This capa rule had 1 match) [[2]](#2) | -|[Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|Query or enumerate registry value (This capa rule had 2 matches) [[2]](#2) | -|[Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|Set registry value (This capa rule had 1 match) [[2]](#2) | -|[Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|Create process on Windows (This capa rule had 3 matches) [[2]](#2) | -|[Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|Terminate process (This capa rule had 2 matches) [[2]](#2) | +|[Command and Control::C2 Communication::Send Data (B0030.001)](../command-and-control/c2-communication.md)|The malware sends hardened HTTP headers disguised as Microsoft Update traffic. [[1]](#1)| +|[Command and Control::C2 Communication::Receive Data (B0030.002)](../command-and-control/c2-communication.md)|The malware receives payloads. [[1]](#1)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|The malware is a dropper that creates multiple files. [[1]](#1)| +|[Anti-Behavioral Analysis::Debugger Detection::Timing/Delay Check GetTickCount (B0001.032)](../anti-behavioral-analysis/debugger-detection.md)|UP007 checks for a time delay via GetTickCount. [[2]](#2)| +|[Micro-Behaviors::Cryptography::Cryptographic Hash::SHA1 (C0029.002)](../micro-behaviors/cryptography/cryptographic-hash.md)|UP007 hashes data using SHA1. [[2]](#2)| +|[Micro-Behaviors::Data::Checksum::CRC32 (C0032.001)](../micro-behaviors/data/checksum.md)|UP007 hashes data with CRC32. [[2]](#2)| +|[Micro-Behaviors::Data::Encode Data::XOR (C0026.002)](../micro-behaviors/data/encode-data.md)|UP007 encodes data using XOR. [[2]](#2)| +|[Micro-Behaviors::File System::Create Directory (C0046)](../micro-behaviors/file-system/create-directory.md)|UP007 creates directories. [[2]](#2)| +|[Micro-Behaviors::File System::Delete File (C0047)](../micro-behaviors/file-system/delete-file.md)|UP007 deletes files. [[2]](#2)| +|[Micro-Behaviors::File System::Get File Attributes (C0049)](../micro-behaviors/file-system/get-file-attributes.md)|UP007 gets file attributes. [[2]](#2)| +|[Micro-Behaviors::File System::Move File (C0063)](../micro-behaviors/file-system/move-file.md)|UP007 moves files. [[2]](#2)| +|[Micro-Behaviors::File System::Read File (C0051)](../micro-behaviors/file-system/read-file.md)|UP007 reads files on Windows. [[2]](#2)| +|[Micro-Behaviors::File System::Set File Attributes (C0050)](../micro-behaviors/file-system/set-file-attributes.md)|UP007 sets file attributes. [[2]](#2)| +|[Micro-Behaviors::File System::Write File (C0052)](../micro-behaviors/file-system/writes-file.md)|UP007 writes files on Windows. [[2]](#2)| +|[Micro-Behaviors::Operating System::Environment Variable::Set Variable (C0034.001)](../micro-behaviors/operating-system/environment-variable.md)|UP007 sets environment variables. [[2]](#2)| +|[Micro-Behaviors::Operating System::Registry::Query Registry Value (C0036.006)](../micro-behaviors/operating-system/registry.md)|UP007 queries or enumerates registry values. [[2]](#2)| +|[Micro-Behaviors::Operating System::Registry::Set Registry Key (C0036.001)](../micro-behaviors/operating-system/registry.md)|UP007 sets registry values. [[2]](#2)| +|[Micro-Behaviors::Process::Create Process (C0017)](../micro-behaviors/process/create-process.md)|UP007 creates a process on Windows. [[2]](#2)| +|[Micro-Behaviors::Process::Terminate Process (C0018)](../micro-behaviors/process/terminate-process.md)|UP007 terminates processes. [[2]](#2)| + ## Indicators of Compromise @@ -92,6 +95,7 @@ SHA256 Hashes - 5b34b3365eb6a6c700b391172849a2668d66a167669018ae3b9555bc2d1e54ab - ec05e37230e6534fa148b8e022f797ad0afe80f699fbd222a46672118663cf00 - b748b61ff6c3ea0c64f2359c44e022c629378aab6d7377e64c6ad0dcc5f78746 + IP Addresses - 59.188.12[.]123 diff --git a/xample-malware/ursnif.md b/xample-malware/ursnif.md index be95e5c..575deba 100644 --- a/xample-malware/ursnif.md +++ b/xample-malware/ursnif.md @@ -1,7 +1,7 @@ - + @@ -24,13 +24,14 @@ # Ursnif -A banking trojan that uses malware macros to evade sandbox detection. Variant of Gozi. +Ursnif is a variant of Gozi. It is a banking trojan that uses malware macros to evade sandbox detection. + ## ATT&CK Techniques |Name|Use| |---|---| -|[Discovery::System Location Discovery::System Language Discovery (T1614.001)](https://attack.mitre.org/techniques/T1614/001)|Get keyboard layout (This capa rule had 1 match) [[6]](#6) | +|[Discovery::System Location Discovery::System Language Discovery (T1614.001)](https://attack.mitre.org/techniques/T1614/001)|Ursnif gets keyboard layouts. [[6]](#6)| See ATT&CK: [Ursnif - Techniques Used](https://attack.mitre.org/software/S0386/). @@ -38,26 +39,29 @@ See ATT&CK: [Ursnif - Techniques Used](https://attack.mitre.org/software/S0386/) |Name|Use| |---|---| -|[Persistance::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|Adds registry entries to ensure automatic execution at every system startup [[4]](#4) | -|[Defense Evasion::Hijack Execution Flow (F0015)](../defense-evasion/hijack-execution-flow.md)|Hooks various DLL exported functions when the component is loaded in their respective Browser application process is running to monitor network traffic [[4]](#4) | -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Uses windows command prompt commands to gather system info, task list, installed drivers, and installed programs [[4]](#4) | -|[Collection::Input Capture (E1056)](../collection/input-capture.md)|Injects HTML into browser session to collect sensitive online banking information when the victim performs their online banking [[5]](#5) | -|[Anti-Static Analysis::Obfuscated Files or Information (E1027)](../defense-evasion/obfuscated-files-or-information.md)|Creates an encrypted Registry key called TorClient to store its data [[2]](#2) | -|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|Log keystrokes via polling (This capa rule had 1 match) [[6]](#6) | +|[Persistance::Registry Run Keys / Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|The malware adds registry entries to ensure automatic execution at system startup. [[4]](#4)| +|[Defense Evasion::Hijack Execution Flow (F0015)](../defense-evasion/hijack-execution-flow.md)|The malware hooks various DLL exported functions when the DLL component is loaded into their respective browser application to monitor network traffic. [[4]](#4)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|The malware uses Window's command prompt commands to gather system info, task list, installed drivers, and installed programs. [[4]](#4)| +|[Collection::Input Capture (E1056)](../collection/input-capture.md)|The malware injects HTML into a browser session to collect sensitive online banking information when the victim performs their online banking. [[5]](#5)| +|[Defense Evasion::Obfuscated Files or Information (E1027)](../anti-static-analysis/executable-code-obfuscation.md)|The malware creates an encrypted Registry key called TorClient to store its data. [[2]](#2)| +|[Impact::Exploit Kit (E1190)](../impact/exploit-kit.md)|Ursnif is sometimes delivered via exploit kit. [[7]](#7)| +|[Collection::Keylogging::Polling (F0002.002)](../collection/keylogging.md)|Ursnif logs keystrokes via polling. [[6]](#6)| + ## MBC Behaviors |Name|Use| |---|---| -|[Anti-Behavioral Analysis::Sandbox Detection::Self Check (B0007.007)](../anti-behavioral-analysis/sandbox-detection.md)|Ursnif uses malware macros to evade sandbox detection - checking whether the filename contains only hexadecimal characters before the extension [[1]](#1) | -|[Execution::Conditional Execution (B0025.004)](../execution/conditional-execution.md)|Macros check if there are at least 50 running processes with a graphical interface, check if a list of blacklisted processes are running, and checks if the application is running in Australia and is NOT affiliated with a select group of networks (Security Research, Hospitals, Universities, Veterans, etc.) [1] [[1]](#1) | -|[Anti-Behavioral Analysis::Virtual Machine Detection::Check Processes (B0009.004)](../anti-behavioral-analysis/virtual-machine-detection.md)|Checks if there are virtual machine processes running (Vbox, vmware, etc) [[1]](#1) | -|[Command and Control::Domain Name Generation (B0031)](../command-and-control/domain-name-generation.md)|Ursnif has used a Domain name generation algorithm in the past [[2]](#2) | -|[Command and Control::C2 Communication::Authenticate (B0030.011)](../command-and-control/c2-communication.md)|Ursnif variant Dreambot authenticates and encrypts traffic to C2 server using TOR [[2]](#2) | -|[Anti-Behavioral Analysis::Debugger Detection::TLS Callbacks (B0001.028)](../anti-behavioral-analysis/debugger-detection.md)|Manipulates TLS Callbacks while injecting to child process [[3]](#3) | -|[Micro-Behavior::Memory::Change Memory Protection (C0008)](../micro-behaviors/memory/change-memory-protection.md)|Changes the PE header of the child process to enable write access to that page, writes 18 bytes of buffer at offset 0x40 from the start of svchost.exe process executable in the target child process. Then changes the region protection back to "read only" to avoid suspicion [[3]](#3) | -|[Execution::Remote Commands (B0011)](../execution/remote-commands.md)|Commands sent by a remote user can archive/upload files, capture screenshots, clear cookies, download execute other files, list running processes, reboot the affected system, steal certificates and cookies, update/download a configuration file, upload a log file which contains stolen information [[5]](#5) | -|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Enumerate PE sections (This capa rule had 1 match) [[6]](#6) | +|[Anti-Behavioral Analysis::Sandbox Detection::Self Check (B0007.007)](../anti-behavioral-analysis/sandbox-detection.md)|Ursnif uses malware macros to evade sandbox detection - checking whether the filename contains only hexadecimal characters before the extension. [[1]](#1)| +|[Execution::Conditional Execution (B0025.004)](../execution/conditional-execution.md)|Macros check if there are at least 50 running processes with a graphical interface, check if a list of blacklisted processes are running, and checks if the application is running in Australia and is NOT affiliated with a select group of networks (Security Research, Hospitals, Universities, Veterans, etc.). [[1]](#1)| +|[Anti-Behavioral Analysis::Virtual Machine Detection::Check Processes (B0009.004)](../anti-behavioral-analysis/virtual-machine-detection.md)|The malware checks if there are virtual machine processes running (Vbox, vmware, etc). [[1]](#1)| +|[Command and Control::Domain Name Generation (B0031)](../command-and-control/domain-name-generation.md)|Previous interations of Ursnif have used a Domain Name Generation algorithm. [[2]](#2)| +|[Command and Control::C2 Communication::Authenticate (B0030.011)](../command-and-control/c2-communication.md)|Ursnif variant Dreambot authenticates and encrypts traffic to the C2 server using TOR. [[2]](#2)| +|[Anti-Behavioral Analysis::Debugger Detection::TLS Callbacks (B0001.028)](../anti-behavioral-analysis/debugger-detection.md)|The malware manipulates TLS Callbacks while injecting into a child process. [[3]](#3)| +|[Micro-Behaviors::Memory::Change Memory Protection (C0008)](../micro-behaviors/memory/change-memory-protection.md)|The malware changes the PE header of the child process to enable write access to that page and writes 18 bytes of buffer at offset 0x40 from the start of svchost.exe in the target child process. The region protection is changed back to "read only" to avoid suspicion. [[3]](#3)| +|[Execution::Remote Commands (B0011)](../execution/remote-commands.md)|The malware commands sent by a remote user can archive/upload files, capture screenshots, clear cookies, download and execute other files, list running processes, reboot the affected system, steal certificates and cookies, update/download a configuration file, and upload a log file which contains stolen information. [[5]](#5)| +|[Discovery::Code Discovery::Enumerate PE Sections (B0046.001)](../discovery/code-discovery.md)|Ursnif enumerates PE sections. [[6]](#6)| + ## Indicators of Compromise @@ -65,6 +69,7 @@ SHA256 Hashes - 6464cf93832a5188d102cce498b4f3be0525ea1b080fec9c4e12fae912984057 - 0b05fb5b97bfc3c82f46b8259a88ae656b1ad294e4c1324d8e8ffd59219005ac - 9350609c8c806a9c1a667fd53926ea85745e1da239df7f3c2aad3e3527bd48d1 + URLS, IPs, and Domains - hxxp://62.138.9[.]11/30030u - hxxp://62.138.9[.]11/vnc32.dll @@ -92,3 +97,4 @@ URLS, IPs, and Domains [6] capa v4.0, analyzed at MITRE on 10/12/2022 +[7] https://www.cyber.nj.gov/threat-profiles/trojan-variants/ursnif diff --git a/xample-malware/vobfus.md b/xample-malware/vobfus.md new file mode 100644 index 0000000..f7adb3a --- /dev/null +++ b/xample-malware/vobfus.md @@ -0,0 +1,83 @@ + +
IDX0022X0038
Aliases
+ + + + + + + + + + + + + + + + + + + + +
IDX0039
AliasesNone
PlatformsWindows
Year2016
Associated ATT&CK SoftwareNone
+ + +# Vobfus + +Vobfus is a Visual Basic worm that spreads across removable media and network shares. Vobfus can also download and execute additional binaries from other malware families. + + +## ATT&CK Techniques + +|Name|Use| +|---|---| +|[Lateral Movement::Lateral Tool Transfer (T1570)](https://attack.mitre.org/techniques/T1570/)|Vobfus drops copies of itself to any external drives or network shares attached to the infected system. [[1]](#1)| + + +## Enhanced ATT&CK Techniques + +|Name|Use| +|---|---| +|[Command and Control::Ingress Tool Transfer (E1105)](../command-and-control/ingress-tool-transfer.md)|Vobfus downloads the latest version of itself from a remote server. [[1]](#1)| +|[Persistence::Registry Run Keys/Startup Folder (F0012)](../persistence/registry-run-keys-startup-folder.md)|Vobfus adds registry keys to enable startup after reboot. [[1]](#1)| +|[Defense Evasion::Hidden Files and Directories::Location (F0005.002)](../defense-evasion/hidden-files-and-directories.md)|Vobfus is located on external drives or network shares and attaches itself to any ZIP or RAR files, removable drives, and network shares. The malware hides all folders in the external drive and drops an executable with the same name and a disguished folder icon. [[1]](#1)| +|[Execution::User Execution (E1204)](../execution/user-execution.md)|The malware relies on user interaction to run the executable. [[1]](#1)| +|[Defense Evasion::Disable or Evade Security Tools (F0004)](../defense-evasion/disable-or-evade-security-tools.md)|Vobfus uses GetModuleHandle API call to check for presence of Avast Antivirus. [[1]](#1)| +|[Persistence::Modify Existing Service (F0011)](../persistence/modify-existing-service.md)|Vobfus disables Windows AutoUpdate on the infected system. The malware patches the first byte of TerminateProcess and TerminateThread API with C3 (RET Instruction) to prevent any external processes from terminating the running instance of the malware. [[1]](#1)| + + +## MBC Behaviors + +|Name|Use| +|---|---| +|[Anti-Behavioral Analysis::Capture Evasion::Encrypted Payloads (B0036.002)](../anti-behavioral-analysis/capture-evasion.md)|Vobfus is downloaded in encrypted form and then decrypted. [[1]](#1)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Vobfus downloads other malware family executables. [[1]](#1)| +|[Anti-Behavioral Analysis::Debugger Evasion (B0002)](../anti-behavioral-analysis/debugger-evasion.md)|Vobfus uses GetModuleHandle API to check for the presence of a debugger. [[1]](#1)| +|[Anti-Behavioral Analysis::Sandbox Detection (B0007)](../anti-behavioral-analysis/sandbox-detection.md)|Vobfus uses GetModuleHandle API to check for the presence of a sandbox. [[1]](#1)| +|[Anti-Behavioral Analysis::Virtual Machine Detection (B0009)](../anti-behavioral-analysis/virtual-machine-detection.md)|Vobfus checks for the presence of virtualization software, such as VMware, VirtualBox, and QEMU, by querying the system registry. [[1]](#1)| + + +## Indicators of Compromise + +Download locations +- %USERPROFILE%muoeyus.exe +- %USERPROFILE%vuvuv.exe +- %USERPROFILE%3s8.exe +- %TEMP%2724921.exe + +Potential File Names +- Passwords.exe +- Porn.exe +- Secret.exe +- Sexy.exe +- x.mpeg [0 byte File] +- Autorun.inf +- Muoeyus.exe + + +## References + +[1] https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/ + + diff --git a/xample-malware/webcobra.md b/xample-malware/webcobra.md index b5fb32c..415d2fc 100644 --- a/xample-malware/webcobra.md +++ b/xample-malware/webcobra.md @@ -2,7 +2,7 @@ - + @@ -25,39 +25,44 @@ # WebCobra -Cryptojacking malware. [[1]](#1) +WebCobra is cryptojacking malware. [[1]](#1) ## ATT&CK Techniques |Name|Use| |---|---| -|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057/)| [[1]](#1)| -|[Discovery::System Time Discovery (T1124)](https://attack.mitre.org/techniques/T1124/)| [[1]](#1)| -|[Discovery::Software Discovery::Security Software Discovery (T1518.001)](https://attack.mitre.org/techniques/T1518/001/)|Learns about security software. [[1]](#1)| -|[Defense Evasion::Deobfuscate/Decode Files or Information (T1140)](https://attack.mitre.org/techniques/T1140/)| [[1]](#1)| -|[Defense Evasion::Indicator Removal on Host::File Deletion (T1070.004)](https://attack.mitre.org/techniques/T1070/004/)| [[1]](#1)| +|[Discovery::File and Directory Discovery (T1083)](https://attack.mitre.org/techniques/T1083/)|The malware searches for various files and directories. [[1]](#1)| +|[Discovery::Query Registry (T1012)](https://attack.mitre.org/techniques/T1012/)|The malware queries certain registry keys. [[1]](#1)| +|[Discovery::Process Discovery (T1057)](https://attack.mitre.org/techniques/T1057/)|The malware identifies running processes on the system. [[1]](#1)| +|[Discovery::System Time Discovery (T1124)](https://attack.mitre.org/techniques/T1124/)|The malware identifies the time/time zone on the system. [[1]](#1)| +|[Discovery::Software Discovery::Security Software Discovery (T1518.001)](https://attack.mitre.org/techniques/T1518/001/)|The malware learns about security software on the system. [[1]](#1)| +|[Defense Evasion::Deobfuscate/Decode Files or Information (T1140)](https://attack.mitre.org/techniques/T1140/)|The malware drops encrypted files and decrypts them on the system. [[1]](#1)| +|[Defense Evasion::Indicator Removal on Host::File Deletion (T1070.004)](https://attack.mitre.org/techniques/T1070/004/)|The malware deletes files to evade detection. [[1]](#1)| + ## Enhanced ATT&CK Techniques |Name|Use| |---|---| -|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Learns about the system so it can drop compatible miner software. [[1]](#1)| -|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|From the command line, drops and unzips a password-protected Cabinet archive file. [[1]](#1)| -|[Defense Evasion::Obfuscated Files or Information (E1027)](../defense-evasion/obfuscated-files-or-information.md)|Obfuscates files. [[1]](#1)| -|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|Injects miner code into a running process. [[1]](#1)| -|[Defense Evasion::Disable or Evade Security Tools (F0004)](../defense-evasion/disable-or-evade-security-tools.md)|Most security products hook some APIs to monitor the behavior of malware. To avoid being found by this technique, WebCobra loads ntdll.dll and user32.dll as data files in memory and overwrites the first 8 bytes of those functions, which unhooks the APIs. [[1]](#1)| +|[Discovery::System Information Discovery (E1082)](../discovery/system-information-discovery.md)|Malware learns about the system so it can drop compatible miner software. [[1]](#1)| +|[Execution::Command and Scripting Interpreter (E1059)](../execution/command-and-scripting-interpreter.md)|From the command line, the malware drops and unzips a password-protected Cabinet archive file. [[1]](#1)| +|[Defense Evasion::Obfuscated Files or Information (E1027)](../defense-evasion/obfuscated-files-or-information.md)|The dropped file is password-protected. Once unzipped, the file contains a DLL file to decrypt the second file (a bin file with an encrypted malicious payload). [[1]](#1)| +|[Defense Evasion::Process Injection (E1055)](../defense-evasion/process-injection.md)|The malware injects miner code into a running process. [[1]](#1)| +|[Defense Evasion::Disable or Evade Security Tools (E1089)](../defense-evasion/disable-or-evade-security-tools.md)|Most security products hook some APIs to monitor the behavior of malware. To avoid being identified by this technique, WebCobra loads ntdll.dll and user32.dll as data files in memory and overwrites the first 8 bytes of those functions, which unhooks the APIs. [[1]](#1)| ## MBC Behaviors |Name|Use| |---|---| -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Downloads and executes Claymore's Zcash miner from a remote server. [[1]](#1)| -|[Execution::Conditional Execution (B0025)](../execution/conditional-execution.md)|Executes differently depending on whether it's running on an x86 or x64 system. [[1]](#1)| -|[Impact::Resource Hijacking (B0018)](../impact/resource-hijacking.md)|Drops software that mines for cryptocurrency: Cryptonight or Claymore's Zcash miner, depending on system architecture. [[1]](#1)| -|[Anti-Behavioral Analysis::Dynamic Analysis Evasion (B0003)](../anti-behavioral-analysis/dynamic-analysis-evasion.md)|Evades dynamic analysis. [[1]](#1)| -|[Anti-Behavioral Analysis::Emulator Evasion (B0005)](../anti-behavioral-analysis/emulator-evasion.md)|Evades emulator-based analysis. [[1]](#1)| -|[Anti-Behavioral Analysis::Virtual Machine Detection (B0009)](../anti-behavioral-analysis/virtual-machine-detection.md)|WebCobra injects malicious code to svchost.exe and uses an infinite loop to check all open windows and to compare each window’s title bar text with a set of strings to determine whether it is running in an isolated, malware analysis environment. [[1]](#1)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|The malware downloads and executes Claymore's Zcash miner from a remote server. [[1]](#1)| +|[Execution::Conditional Execution (B0025)](../execution/conditional-execution.md)|The malware executes differently depending on whether it's running on an x86 or x64 system. [[1]](#1)| +|[Impact::Resource Hijacking::Cryptojacking (B0018.002)](../impact/resource-hijacking.md)|The malware drops software that mines for cryptocurrency, depending on the system architecture. If the system has x86 architecture, the malware drops Cryptonight miner. If the system has x64 architecture, the malware drops Claymore's Zcash miner. [[1]](#1)| +|[Anti-Behavioral Analysis::Dynamic Analysis Evasion::Alternative ntdll.dll (B0003.001)](../anti-behavioral-analysis/dynamic-analysis-evasion.md)|The malware loads ntdll.dll and user32.dll as data files and overwrites the first 8 bytes of those functions to avoid API hooking by security products. [[1]](#1)| +|[Anti-Behavioral Analysis::Emulator Evasion::Extra Loops/Time Locks (B0005.004)](../anti-behavioral-analysis/emulator-evasion.md)|The malware evades emulator-based analysis by using an infinite loop to check all open windows and compare each window's title bar to a list of strings. [[1]](#1)| +|[Anti-Behavioral Analysis::Virtual Machine Detection::Check Windows - Title Bars (B0009.022)](../anti-behavioral-analysis/virtual-machine-detection.md)|WebCobra injects malicious code in to svchost.exe and uses an infinite loop to check all open windows and to compare each window’s title bar text with a set of strings to determine whether it is running in a VM. [[1]](#1)| +|[Discovery::Analysis Tool Discovery::Process Detection - PCAP Utilities (B0013.004)](../discovery/analysis-tool-discovery.md)|When infecting a x64 architecture system, the malware terminates if Wireshark is running on the system. [[1]](#1)| + ## Indicators of Compromise diff --git a/xample-malware/yispecter.md b/xample-malware/yispecter.md index 32cb888..84e9b05 100644 --- a/xample-malware/yispecter.md +++ b/xample-malware/yispecter.md @@ -2,7 +2,7 @@
IDX0023X0040
Aliases
- + @@ -25,7 +25,7 @@ # YiSpecter -YiSpecter is Apple iOS malware that can download, install and launch arbitrary iOS apps, replace existing apps with those it downloads, hijack other apps’ execution to display advertisements, change Safari’s default search engine, bookmarks and opened pages, and upload device information to a C2 server. It uses tricks to hide its icons from iOS’s SpringBoard, which prevents the user from finding and deleting it. The components also use the same name and logos of system apps to trick iOS power users. [[1]](#1) +YiSpecter is an Apple iOS malware that can download, install and launch arbitrary iOS apps, replace existing apps with the downloads, hijack other apps’ execution to display advertisements, change Safari’s default search engine, bookmark and open pages, and upload device information to a C2 server. It uses tricks to hide its icons from iOS’s SpringBoard, which prevents the user from finding and deleting it. The components also use the same name and logos of system apps to trick iOS power users. [[1]](#1) ## ATT&CK Techniques @@ -35,20 +35,21 @@ See ATT&CK: [YiSpecter - Techniques Used](https://attack.mitre.org/software/S031 |Name|Use| |---|---| -|[Defense Evasion::Hide Artifacts (E1564)](../defense-evasion/hide-artifacts.md)|Hides icons from iOS's SpringBoard as well as use the same name and logos of system apps to trick iOS power users [[1]](#1)| -|[Persistence::Modify Existing Service (F0011)](../persistence/modify-existing-service.md)|Hijacks other installed applications' launch routines to use "ADPage" (an installed malicious app) to display advertisements [[1]](#1)| -|[Lateral Movement::Supply Chain Compromise::Exploit Private APIs (E1195.m02)](../lateral-movement/supply-chain-compromise.md)|Use of the private api allowed both Installation of malicious apps and uninstallation of legitimate apps without user notification [[1]](#1)| -|[Lateral Movement::Supply Chain Compromise::Abuse Enterprise Certificates (E1195.m01)](../lateral-movement/supply-chain-compromise.md)|YiSpecter's malicious apps were signed with three iOS enterprise certificates issued by Apple so they can be installed as enterprise apps on non-jailbroken iOS devices via in-house distribution [[1]](#1)| -|[Impact::Generate Traffic From Victim::Advertisement Replacement Fraud (E1643.m02)](../impact/generate-traffic-from-victim.md)|Displays brief advertisements whenever the user opens applications on their phone [[1]](#1)| +|[Defense Evasion::Hide Artifacts (E1564)](../defense-evasion/hide-artifacts.md)|The malware hides icons from iOS's SpringBoard and use the same name and logos of system apps to trick iOS power users. [[1]](#1)| +|[Persistence::Modify Existing Service (F0011)](../persistence/modify-existing-service.md)|The malware hijacks other installed applications' launch routines to use "ADPage" (an installed malicious app) to display advertisements. [[1]](#1)| +|[Lateral Movement::Supply Chain Compromise::Exploit Private APIs (E1195.m02)](../lateral-movement/supply-chain-compromise.md)|Within the malware, the private API allows installation of malicious apps and uninstallation of legitimate apps without user notification. [[1]](#1)| +|[Lateral Movement::Supply Chain Compromise::Abuse Enterprise Certificates (E1195.m01)](../lateral-movement/supply-chain-compromise.md)|YiSpecter's malicious apps were signed with three iOS enterprise certificates issued by Apple so they can be installed as enterprise apps on non-jailbroken iOS devices via in-house distribution. [[1]](#1)| +|[Impact::Generate Traffic from Victim::Advertisement Replacement Fraud (E1643.m02)](../impact/generate-traffic-from-victim.md)|The malware displays brief advertisements whenever the user opens applications on their phone. [[1]](#1)| ## MBC Behaviors |Name|Use| |---|---| -|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|Can download and install arbitrary iOS apps [[1]](#1)| -|[Command and Control::C2 Communication::Send System Information (B0030.006)](../command-and-control/c2-communication.md)|Connects to the command and control server using HTTP to send device information [[1]](#1)| -|[Defense Evasion::Install Insecure or Malicious Configuration (B0047)](../defense-evasion/install-insecure-or-malicious-configuration.md)|Changes iOS Safari's default configuration [[1]](#1)| +|[Execution::Install Additional Program (B0023)](../execution/install-additional-program.md)|The malware can download and install arbitrary iOS apps. [[1]](#1)| +|[Command and Control::C2 Communication::Send System Information (B0030.006)](../command-and-control/c2-communication.md)|The malware connects to the C2 server using HTTP to send device information. [[1]](#1)| +|[Defense Evasion::Install Insecure or Malicious Configuration (B0047)](../defense-evasion/install-insecure-or-malicious-configuration.md)|The malware changes iOS Safari's default configuration. [[1]](#1)| + ## Indicators of Compromise
IDX0024X0041
Aliases