ATT&CKReferencesForcepoint Felismus Mar 2017

Forcepoint Felismus Mar 2017

Somerville, L. and Toro, A. (2017, March 30). Playing Cat & Mouse: Introducing the Felismus Malware. Retrieved November 16, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareFelismus

Felismus collects the victim LAN IP address and sends it to the C2 server.

T1033
System Owner/User Discovery
MalwareFelismus

Felismus collects the current username and sends it to the C2 server.

T1059.003
Windows Command Shell
MalwareFelismus

Felismus uses command line for execution.

T1071.001
Web Protocols
MalwareFelismus

Felismus uses HTTP for C2.

T1082
System Information Discovery
MalwareFelismus

Felismus collects the system information, including hostname and OS version, and sends it to the C2 server.

T1105
Ingress Tool Transfer
MalwareFelismus

Felismus can download files from remote servers.

T1132.001
Standard Encoding
MalwareFelismus

Some Felismus samples use a custom method for C2 traffic that utilizes Base64.

T1518.001
Security Software Discovery
MalwareFelismus

Felismus checks for processes associated with anti-virus vendors.

T1573.001
Symmetric Cryptography
MalwareFelismus

Some Felismus samples use a custom encryption method for C2 traffic that utilizes AES and multiple keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.