Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareZeus Panda | Zeus Panda checks for the existence of a Registry key and if it contains certain values. |
| T1027.013 Encrypted/Encoded File |
MalwareZeus Panda | Zeus Panda encrypts strings with XOR. Zeus Panda also encrypts all configuration and settings in AES and RC4. |
| T1055.002 Portable Executable Injection |
MalwareZeus Panda | Zeus Panda checks processes on the system and if they meet the necessary requirements, it injects into that process. |
| T1056.001 Keylogging |
MalwareZeus Panda | Zeus Panda can perform keylogging on the victim’s machine by hooking the functions TranslateMessage and WM_KEYDOWN. |
| T1056.004 Credential API Hooking |
MalwareZeus Panda | Zeus Panda hooks processes by leveraging its own IAT hooked functions. |
| T1057 Process Discovery |
MalwareZeus Panda | Zeus Panda checks for running processes on the victim’s machine. |
| T1059 Command and Scripting Interpreter |
MalwareZeus Panda | Zeus Panda can launch remote scripts on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareZeus Panda | Zeus Panda can launch an interface where it can execute several commands on the victim’s PC. |
| T1070.004 File Deletion |
MalwareZeus Panda | Zeus Panda has a command to delete a file. It also can uninstall scripts and delete files to cover its track. |
| T1082 System Information Discovery |
MalwareZeus Panda | Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system. |
| T1083 File and Directory Discovery |
MalwareZeus Panda | Zeus Panda searches for specific directories on the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareZeus Panda | Zeus Panda can download additional malware plug-in modules and execute them on the victim’s machine. |
| T1112 Modify Registry |
MalwareZeus Panda | Zeus Panda modifies several Registry keys under |
| T1113 Screen Capture |
MalwareZeus Panda | Zeus Panda can take screenshots of the victim’s machine. |
| T1115 Clipboard Data |
MalwareZeus Panda | Zeus Panda can hook GetClipboardData function to watch for clipboard pastes to collect. |
| T1124 System Time Discovery |
MalwareZeus Panda | Zeus Panda collects the current system time (UTC) and sends it back to the C2 server. |
| T1518.001 Security Software Discovery |
MalwareZeus Panda | Zeus Panda checks to see if anti-virus, anti-spyware, or firewall products are installed in the victim’s environment. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareZeus Panda | Zeus Panda adds persistence by creating Registry Run keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.