Brumaghin, E., et al. (2017, November 02). Poisoning the Well: Banking Trojan Targets Google Search Results. Retrieved November 5, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwareZeus Panda | Zeus Panda obfuscates the macro commands in its initial payload. |
| T1027.013 Encrypted/Encoded File |
MalwareZeus Panda | Zeus Panda encrypts strings with XOR. Zeus Panda also encrypts all configuration and settings in AES and RC4. |
| T1059.001 PowerShell |
MalwareZeus Panda | Zeus Panda uses PowerShell to download and execute the payload. |
| T1071.001 Web Protocols |
MalwareZeus Panda | Zeus Panda uses HTTP for C2 communications. |
| T1082 System Information Discovery |
MalwareZeus Panda | Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareZeus Panda | Zeus Panda decrypts strings in the code during the execution process. |
| T1518.001 Security Software Discovery |
MalwareZeus Panda | Zeus Panda checks to see if anti-virus, anti-spyware, or firewall products are installed in the victim’s environment. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareZeus Panda | Zeus Panda adds persistence by creating Registry Run keys. |
| T1614.001 System Language Discovery |
MalwareZeus Panda | Zeus Panda queries the system's keyboard mapping to determine the language used on the system. It will terminate execution if it detects LANG_RUSSIAN, LANG_BELARUSIAN, LANG_KAZAK, or LANG_UKRAINIAN. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.