Cherepanov, A., Lipovsky, R. (2018, October 11). New TeleBots backdoor: First evidence linking Industroyer to NotPetya. Retrieved November 27, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.011 Fileless Storage |
MalwareExaramel for Windows | Exaramel for Windows stores the backdoor's configuration in the Registry in XML format. |
| T1027.013 Encrypted/Encoded File |
MalwareExaramel for Linux | Exaramel for Linux uses RC4 for encrypting the configuration. |
| T1036.004 Masquerade Task or Service |
MalwareExaramel for Windows | The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV” in an apparent attempt to masquerade as a legitimate service. |
| T1053.003 Cron |
MalwareExaramel for Linux | Exaramel for Linux uses crontab for persistence if it does not have root privileges. |
| T1059.003 Windows Command Shell |
MalwareExaramel for Windows | Exaramel for Windows has a command to launch a remote shell and executes commands on the victim’s machine. |
| T1059.004 Unix Shell |
MalwareExaramel for Linux | Exaramel for Linux has a command to execute a shell command on the system. |
| T1059.005 Visual Basic |
MalwareExaramel for Windows | Exaramel for Windows has a command to execute VBS scripts on the victim’s machine. |
| T1071.001 Web Protocols |
MalwareExaramel for Linux | Exaramel for Linux uses HTTPS for C2 communications. |
| T1074.001 Local Data Staging |
MalwareExaramel for Windows | Exaramel for Windows specifies a path to store files scheduled for exfiltration. |
| T1105 Ingress Tool Transfer |
MalwareExaramel for Linux | Exaramel for Linux has a command to download a file from and to a remote C2 server. |
| T1112 Modify Registry |
MalwareExaramel for Windows | Exaramel for Windows adds the configuration to the Registry in XML format. |
| T1543.002 Systemd Service |
MalwareExaramel for Linux | Exaramel for Linux has a hardcoded location under systemd that it uses to achieve persistence if it is running as root. |
| T1543.003 Windows Service |
MalwareExaramel for Windows | The Exaramel for Windows dropper creates and starts a Windows service named wsmprovav with the description “Windows Check AV.” |
| T1560 Archive Collected Data |
MalwareExaramel for Windows | Exaramel for Windows automatically encrypts files before sending them to the C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.