ATT&CKReferencesESET GreyEnergy Oct 2018

ESET GreyEnergy Oct 2018

Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareGreyEnergy

GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine.

T1007
System Service Discovery
MalwareGreyEnergy

GreyEnergy enumerates all Windows services.

T1012
Query Registry
MalwareFELIXROOT

FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry.

T1016
System Network Configuration Discovery
MalwareFELIXROOT

FELIXROOT collects information about the network including the IP address and DHCP server.

T1027.002
Software Packing
MalwareGreyEnergy

GreyEnergy is packed for obfuscation.

T1027.013
Encrypted/Encoded File
MalwareGreyEnergy

GreyEnergy encrypts its configuration files with AES-256 and also encrypts its strings.

T1027.013
Encrypted/Encoded File
MalwareFELIXROOT

FELIXROOT encrypts strings in the backdoor using a custom XOR algorithm.

T1033
System Owner/User Discovery
MalwareFELIXROOT

FELIXROOT collects the username from the victim’s machine.

T1047
Windows Management Instrumentation
MalwareFELIXROOT

FELIXROOT uses WMI to query the Windows Registry.

T1055.002
Portable Executable Injection
MalwareGreyEnergy

GreyEnergy has a module to inject a PE binary into a remote process.

T1056.001
Keylogging
MalwareGreyEnergy

GreyEnergy has a module to harvest pressed keystrokes.

T1057
Process Discovery
MalwareFELIXROOT

FELIXROOT collects a list of running processes.

T1059.003
Windows Command Shell
MalwareGreyEnergy

GreyEnergy uses cmd.exe to execute itself in-memory.

T1059.003
Windows Command Shell
MalwareFELIXROOT

FELIXROOT executes batch scripts on the victim’s machine, and can launch a reverse shell for command execution.

T1070.004
File Deletion
MalwareGreyEnergy

GreyEnergy can securely delete a file by hooking into the DeleteFileA and DeleteFileW functions in the Windows API.

T1071.001
Web Protocols
MalwareGreyEnergy

GreyEnergy uses HTTP and HTTPS for C2 communications.

T1071.001
Web Protocols
MalwareFELIXROOT

FELIXROOT uses HTTP and HTTPS to communicate with the C2 server.

T1082
System Information Discovery
MalwareFELIXROOT

FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type.

T1090.003
Multi-hop Proxy
MalwareGreyEnergy

GreyEnergy has used Tor relays for Command and Control servers.

T1105
Ingress Tool Transfer
MalwareFELIXROOT

FELIXROOT downloads and uploads files to and from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareGreyEnergy

GreyEnergy can download additional modules and payloads.

T1112
Modify Registry
MalwareGreyEnergy

GreyEnergy modifies conditions in the Registry and adds keys.

T1124
System Time Discovery
MalwareFELIXROOT

FELIXROOT gathers the time zone information from the victim’s machine.

T1218.011
Rundll32
MalwareGreyEnergy

GreyEnergy uses PsExec locally in order to execute rundll32.exe at the highest privileges (NTAUTHORITY\SYSTEM).

T1218.011
Rundll32
MalwareFELIXROOT

FELIXROOT uses Rundll32 for executing the dropper program.

T1518.001
Security Software Discovery
MalwareFELIXROOT

FELIXROOT checks for installed security software like antivirus and firewall.

T1543.003
Windows Service
MalwareGreyEnergy

GreyEnergy chooses a service, drops a DLL file, and writes it to that serviceDLL Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwareFELIXROOT

FELIXROOT adds a shortcut file to the startup folder for persistence.

T1547.009
Shortcut Modification
MalwareFELIXROOT

FELIXROOT creates a .LNK file for persistence.

T1553.002
Code Signing
MalwareGreyEnergy

GreyEnergy digitally signs the malware with a code-signing certificate.

T1573.001
Symmetric Cryptography
MalwareGreyEnergy

GreyEnergy encrypts communications using AES256.

T1573.002
Asymmetric Cryptography
MalwareGreyEnergy

GreyEnergy encrypts communications using RSA-2048.

T1680
Local Storage Discovery
MalwareFELIXROOT

FELIXROOT collects the victim’s volume serial number.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.