ATT&CKReferencesGDATA Zeus Panda June 2017

GDATA Zeus Panda June 2017

Ebach, L. (2017, June 22). Analysis Results of Zeus.Variant.Panda. Retrieved November 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareZeus Panda

Zeus Panda checks for the existence of a Registry key and if it contains certain values.

T1027.013
Encrypted/Encoded File
MalwareZeus Panda

Zeus Panda encrypts strings with XOR. Zeus Panda also encrypts all configuration and settings in AES and RC4.

T1055.002
Portable Executable Injection
MalwareZeus Panda

Zeus Panda checks processes on the system and if they meet the necessary requirements, it injects into that process.

T1056.001
Keylogging
MalwareZeus Panda

Zeus Panda can perform keylogging on the victim’s machine by hooking the functions TranslateMessage and WM_KEYDOWN.

T1056.004
Credential API Hooking
MalwareZeus Panda

Zeus Panda hooks processes by leveraging its own IAT hooked functions.

T1057
Process Discovery
MalwareZeus Panda

Zeus Panda checks for running processes on the victim’s machine.

T1059
Command and Scripting Interpreter
MalwareZeus Panda

Zeus Panda can launch remote scripts on the victim’s machine.

T1059.003
Windows Command Shell
MalwareZeus Panda

Zeus Panda can launch an interface where it can execute several commands on the victim’s PC.

T1070.004
File Deletion
MalwareZeus Panda

Zeus Panda has a command to delete a file. It also can uninstall scripts and delete files to cover its track.

T1082
System Information Discovery
MalwareZeus Panda

Zeus Panda collects the OS version, system architecture, computer name, product ID, install date, and information on the keyboard mapping to determine the language used on the system.

T1083
File and Directory Discovery
MalwareZeus Panda

Zeus Panda searches for specific directories on the victim’s machine.

T1105
Ingress Tool Transfer
MalwareZeus Panda

Zeus Panda can download additional malware plug-in modules and execute them on the victim’s machine.

T1112
Modify Registry
MalwareZeus Panda

Zeus Panda modifies several Registry keys under HKCU\Software\Microsoft\Internet Explorer\ PhishingFilter\ to disable phishing filters.

T1113
Screen Capture
MalwareZeus Panda

Zeus Panda can take screenshots of the victim’s machine.

T1115
Clipboard Data
MalwareZeus Panda

Zeus Panda can hook GetClipboardData function to watch for clipboard pastes to collect.

T1124
System Time Discovery
MalwareZeus Panda

Zeus Panda collects the current system time (UTC) and sends it back to the C2 server.

T1518.001
Security Software Discovery
MalwareZeus Panda

Zeus Panda checks to see if anti-virus, anti-spyware, or firewall products are installed in the victim’s environment.

T1547.001
Registry Run Keys / Startup Folder
MalwareZeus Panda

Zeus Panda adds persistence by creating Registry Run keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.