ATT&CKReferencesTalos Zeus Panda Nov 2017

Talos Zeus Panda Nov 2017

Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareZeus Panda

Zeus Panda obfuscates the macro commands in its initial payload.

T1027.013
Encrypted/Encoded File
MalwareZeus Panda

Zeus Panda encrypts strings with XOR. Zeus Panda also encrypts all configuration and settings in AES and RC4.

T1059.001
PowerShell
MalwareZeus Panda

Zeus Panda uses PowerShell to download and execute the payload.

T1071.001
Web Protocols
MalwareZeus Panda

Zeus Panda uses HTTP for C2 communications.

T1082
System Information Discovery
MalwareZeus Panda

Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system.

T1140
Deobfuscate/Decode Files or Information
MalwareZeus Panda

Zeus Panda decrypts strings in the code during the execution process.

T1518.001
Security Software Discovery
MalwareZeus Panda

Zeus Panda checks to see if anti-virus, anti-spyware, or firewall products are installed in the victim’s environment.

T1547.001
Registry Run Keys / Startup Folder
MalwareZeus Panda

Zeus Panda adds persistence by creating Registry Run keys.

T1614.001
System Language Discovery
MalwareZeus Panda

Zeus Panda queries the system's keyboard mapping to determine the language used on the system. It will terminate execution if it detects LANG_RUSSIAN, LANG_BELARUSIAN, LANG_KAZAK, or LANG_UKRAINIAN.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.