CISA. (2020, July 16). MAR-10296782-2.v1 – WELLMESS. Retrieved September 24, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareWellMess | WellMess can use junk data in the Base64 string for additional obfuscation. |
| T1005 Data from Local System |
MalwareWellMess | WellMess can send files from the victim machine to C2. |
| T1016 System Network Configuration Discovery |
MalwareWellMess | WellMess can identify the IP address and user domain on the target machine. |
| T1033 System Owner/User Discovery |
MalwareWellMess | WellMess can collect the username on the victim machine to send to C2. |
| T1059.001 PowerShell |
MalwareWellMess | WellMess can execute PowerShell scripts received from C2. |
| T1069.002 Domain Groups |
MalwareWellMess | WellMess can identify domain group membership for the current user. |
| T1071.001 Web Protocols |
MalwareWellMess | WellMess can use HTTP and HTTPS in C2 communications. |
| T1082 System Information Discovery |
MalwareWellMess | WellMess can identify the computer name of a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareWellMess | WellMess can write files to a compromised host. |
| T1132.001 Standard Encoding |
MalwareWellMess | WellMess has used Base64 encoding to uniquely identify communication to and from the C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWellMess | WellMess can decode and decrypt data received from C2. |
| T1573.001 Symmetric Cryptography |
MalwareWellMess | WellMess can encrypt HTTP POST data using RC6 and a dynamically generated AES key encrypted with a hard coded RSA public key. |
| T1573.002 Asymmetric Cryptography |
MalwareWellMess | WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.