ATT&CKReferencesFysbis Dr Web Analysis

Fysbis Dr Web Analysis

Doctor Web. (2014, November 21). Linux.BackDoor.Fysbis.1. Retrieved December 7, 2017.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareFysbis

Fysbis has been encrypted using XOR and RC4.

T1036.004
Masquerade Task or Service
MalwareFysbis

Fysbis has masqueraded as the rsyncd and dbus-inotifier services.

T1036.005
Match Legitimate Resource Name or Location
MalwareFysbis

Fysbis has masqueraded as trusted software rsyncd and dbus-inotifier.

T1057
Process Discovery
MalwareFysbis

Fysbis can collect information about running processes.

T1070.004
File Deletion
MalwareFysbis

Fysbis has the ability to delete files.

T1083
File and Directory Discovery
MalwareFysbis

Fysbis has the ability to search for files.

T1132.001
Standard Encoding
MalwareFysbis

Fysbis can use Base64 to encode its C2 traffic.

T1543.002
Systemd Service
MalwareFysbis

Fysbis has established persistence using a systemd service.

T1547.013
XDG Autostart Entries
MalwareFysbis

If executing without root privileges, Fysbis adds a `.desktop` configuration file to the user's `~/.config/autostart` directory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.