Cherepanov, A. (2018, October). GREYENERGY A successor to BlackEnergy. Retrieved November 15, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareGreyEnergy | GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine. |
| T1007 System Service Discovery |
MalwareGreyEnergy | GreyEnergy enumerates all Windows services. |
| T1012 Query Registry |
MalwareFELIXROOT | FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry. |
| T1016 System Network Configuration Discovery |
MalwareFELIXROOT | FELIXROOT collects information about the network including the IP address and DHCP server. |
| T1027.002 Software Packing |
MalwareGreyEnergy | GreyEnergy is packed for obfuscation. |
| T1027.013 Encrypted/Encoded File |
MalwareGreyEnergy | GreyEnergy encrypts its configuration files with AES-256 and also encrypts its strings. |
| T1027.013 Encrypted/Encoded File |
MalwareFELIXROOT | FELIXROOT encrypts strings in the backdoor using a custom XOR algorithm. |
| T1033 System Owner/User Discovery |
MalwareFELIXROOT | FELIXROOT collects the username from the victim’s machine. |
| T1047 Windows Management Instrumentation |
MalwareFELIXROOT | FELIXROOT uses WMI to query the Windows Registry. |
| T1055.002 Portable Executable Injection |
MalwareGreyEnergy | GreyEnergy has a module to inject a PE binary into a remote process. |
| T1056.001 Keylogging |
MalwareGreyEnergy | GreyEnergy has a module to harvest pressed keystrokes. |
| T1057 Process Discovery |
MalwareFELIXROOT | FELIXROOT collects a list of running processes. |
| T1059.003 Windows Command Shell |
MalwareGreyEnergy | GreyEnergy uses cmd.exe to execute itself in-memory. |
| T1059.003 Windows Command Shell |
MalwareFELIXROOT | FELIXROOT executes batch scripts on the victim’s machine, and can launch a reverse shell for command execution. |
| T1070.004 File Deletion |
MalwareGreyEnergy | GreyEnergy can securely delete a file by hooking into the DeleteFileA and DeleteFileW functions in the Windows API. |
| T1071.001 Web Protocols |
MalwareGreyEnergy | GreyEnergy uses HTTP and HTTPS for C2 communications. |
| T1071.001 Web Protocols |
MalwareFELIXROOT | FELIXROOT uses HTTP and HTTPS to communicate with the C2 server. |
| T1082 System Information Discovery |
MalwareFELIXROOT | FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type. |
| T1090.003 Multi-hop Proxy |
MalwareGreyEnergy | GreyEnergy has used Tor relays for Command and Control servers. |
| T1105 Ingress Tool Transfer |
MalwareFELIXROOT | FELIXROOT downloads and uploads files to and from the victim’s machine. |
| T1105 Ingress Tool Transfer |
MalwareGreyEnergy | GreyEnergy can download additional modules and payloads. |
| T1112 Modify Registry |
MalwareGreyEnergy | GreyEnergy modifies conditions in the Registry and adds keys. |
| T1124 System Time Discovery |
MalwareFELIXROOT | FELIXROOT gathers the time zone information from the victim’s machine. |
| T1218.011 Rundll32 |
MalwareGreyEnergy | GreyEnergy uses PsExec locally in order to execute rundll32.exe at the highest privileges (NTAUTHORITY\SYSTEM). |
| T1218.011 Rundll32 |
MalwareFELIXROOT | FELIXROOT uses Rundll32 for executing the dropper program. |
| T1518.001 Security Software Discovery |
MalwareFELIXROOT | FELIXROOT checks for installed security software like antivirus and firewall. |
| T1543.003 Windows Service |
MalwareGreyEnergy | GreyEnergy chooses a service, drops a DLL file, and writes it to that serviceDLL Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareFELIXROOT | FELIXROOT adds a shortcut file to the startup folder for persistence. |
| T1547.009 Shortcut Modification |
MalwareFELIXROOT | FELIXROOT creates a .LNK file for persistence. |
| T1553.002 Code Signing |
MalwareGreyEnergy | GreyEnergy digitally signs the malware with a code-signing certificate. |
| T1573.001 Symmetric Cryptography |
MalwareGreyEnergy | GreyEnergy encrypts communications using AES256. |
| T1573.002 Asymmetric Cryptography |
MalwareGreyEnergy | GreyEnergy encrypts communications using RSA-2048. |
| T1680 Local Storage Discovery |
MalwareFELIXROOT | FELIXROOT collects the victim’s volume serial number. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.