ATT&CKReferencesTrend Micro Daserf Nov 2017

Trend Micro Daserf Nov 2017

Chen, J. and Hsieh, M. (2017, November 7). REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography. Retrieved December 27, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1001.002
Steganography
MalwareDaserf

Daserf can use steganography to hide malicious code downloaded to the victim.

T1027
Obfuscated Files or Information
MalwareDaserf

Daserf uses encrypted Windows APIs and also encrypts data using the alternative base64+RC4 or the Caesar cipher.

T1027.002
Software Packing
MalwareDaserf

A version of Daserf uses the MPRESS packer.

T1027.005
Indicator Removal from Tools
MalwareDaserf

Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection.

T1056.001
Keylogging
MalwareDaserf

Daserf can log keystrokes.

T1059.003
Windows Command Shell
MalwareDaserf

Daserf can execute shell commands.

T1105
Ingress Tool Transfer
MalwareDaserf

Daserf can download remote files.

T1113
Screen Capture
MalwareDaserf

Daserf can take screenshots.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.