ATT&CKReferencesCheckpoint Dridex Jan 2021

Checkpoint Dridex Jan 2021

Check Point Research. (2021, January 4). Stopping Serial Killer: Catching the Next Strike. Retrieved September 7, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareDridex

Dridex's strings are obfuscated using RC4.

T1071.001
Web Protocols
MalwareDridex

Dridex has used POST requests and HTTPS for C2 communications.

T1082
System Information Discovery
MalwareDridex

Dridex has collected the computer name and OS architecture information from the system.

T1090
Proxy
MalwareDridex

Dridex contains a backconnect module for tunneling network traffic through a victim's computer. Infected computers become part of a P2P botnet that can relay C2 traffic to other infected peers.

T1090.003
Multi-hop Proxy
MalwareDridex

Dridex can use multiple layers of proxy servers to hide terminal nodes in its infrastructure.

T1106
Native API
MalwareDridex

Dridex has used the OutputDebugStringW function to avoid malware analysis as part of its anti-debugging technique.

T1204.002
Malicious File
MalwareDridex

Dridex has relied upon users clicking on a malicious attachment delivered through spearphishing.

T1518
Software Discovery
MalwareDridex

Dridex has collected a list of installed software on the system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.