Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareElise | Elise executes |
| T1016 System Network Configuration Discovery |
MalwareElise | Elise executes |
| T1027.013 Encrypted/Encoded File |
MalwareElise | Elise encrypts several of its files, including configuration files. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareElise | If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network. |
| T1055.001 Dynamic-link Library Injection |
MalwareElise | Elise injects DLL files into iexplore.exe. |
| T1070.006 Timestomp |
MalwareElise | Elise performs timestomping of a CAB file it creates. |
| T1071.001 Web Protocols |
MalwareElise | Elise communicates over HTTP or HTTPS for C2. |
| T1082 System Information Discovery |
MalwareElise | Elise executes |
| T1083 File and Directory Discovery |
MalwareElise | A variant of Elise executes |
| T1087.001 Local Account |
MalwareElise | Elise executes |
| T1132.001 Standard Encoding |
MalwareElise | Elise exfiltrates data using cookie values that are Base64-encoded. |
| T1218.011 Rundll32 |
MalwareElise | After copying itself to a DLL file, a variant of Elise calls the DLL file using rundll32.exe. |
| T1543.003 Windows Service |
MalwareElise | Elise configures itself as a service. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareElise | If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: |
| T1573.001 Symmetric Cryptography |
MalwareElise | Elise encrypts exfiltrated data with RC4. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.