ATT&CKReferencesF-Secure CozyDuke

F-Secure CozyDuke

F-Secure Labs. (2015, April 22). CozyDuke: Malware Analysis. Retrieved December 10, 2015.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareCozyCar

CozyCar has executed Mimikatz to harvest stored credentials from the victim and further victim penetration.

T1003.002
Security Account Manager
MalwareCozyCar

Password stealer and NTLM stealer modules in CozyCar harvest stored credentials from the victim, including credentials used as part of Windows NTLM user authentication.

T1027.013
Encrypted/Encoded File
MalwareCozyCar

The payload of CozyCar is encrypted with simple XOR with a rotating key. The CozyCar configuration file has been encrypted with RC4 keys.

T1036.003
Rename Legitimate Utilities
MalwareCozyCar

The CozyCar dropper has masqueraded a copy of the infected system's rundll32.exe executable that was moved to the malware's install directory and renamed according to a predefined configuration file.

T1053.005
Scheduled Task
MalwareCozyCar

One persistence mechanism used by CozyCar is to register itself as a scheduled task.

T1059.003
Windows Command Shell
MalwareCozyCar

A module in CozyCar allows arbitrary commands to be executed by invoking C:\Windows\System32\cmd.exe.

T1071.001
Web Protocols
MalwareCozyCar

CozyCar's main method of communicating with its C2 servers is using HTTP or HTTPS.

T1082
System Information Discovery
MalwareCozyCar

A system info module in CozyCar gathers information on the victim host’s configuration.

T1102.002
Bidirectional Communication
MalwareCozyCar

CozyCar uses Twitter as a backup C2 channel to Twitter accounts specified in its configuration file.

T1218.011
Rundll32
MalwareCozyCar

The CozyCar dropper copies the system file rundll32.exe to the install location for the malware, then uses the copy of rundll32.exe to load and execute the main CozyCar component.

T1497
Virtualization/Sandbox Evasion
MalwareCozyCar

Some versions of CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. If it detects that it is, it will exit.

T1518.001
Security Software Discovery
MalwareCozyCar

The main CozyCar dropper checks whether the victim has an anti-virus product installed. If the installed product is on a predetermined list, the dropper will exit.

T1543.003
Windows Service
MalwareCozyCar

One persistence mechanism used by CozyCar is to register itself as a Windows service.

T1547.001
Registry Run Keys / Startup Folder
MalwareCozyCar

One persistence mechanism used by CozyCar is to set itself to be executed at system startup by adding a Registry value under one of the following Registry keys: <br>HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ <br>HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ <br>HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run <br>HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.