ATT&CKReferencesCISA WellMess July 2020

CISA WellMess July 2020

CISA. (2020, July 16). MAR-10296782-2.v1 – WELLMESS. Retrieved September 24, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareWellMess

WellMess can use junk data in the Base64 string for additional obfuscation.

T1005
Data from Local System
MalwareWellMess

WellMess can send files from the victim machine to C2.

T1016
System Network Configuration Discovery
MalwareWellMess

WellMess can identify the IP address and user domain on the target machine.

T1033
System Owner/User Discovery
MalwareWellMess

WellMess can collect the username on the victim machine to send to C2.

T1059.001
PowerShell
MalwareWellMess

WellMess can execute PowerShell scripts received from C2.

T1069.002
Domain Groups
MalwareWellMess

WellMess can identify domain group membership for the current user.

T1071.001
Web Protocols
MalwareWellMess

WellMess can use HTTP and HTTPS in C2 communications.

T1082
System Information Discovery
MalwareWellMess

WellMess can identify the computer name of a compromised host.

T1105
Ingress Tool Transfer
MalwareWellMess

WellMess can write files to a compromised host.

T1132.001
Standard Encoding
MalwareWellMess

WellMess has used Base64 encoding to uniquely identify communication to and from the C2.

T1140
Deobfuscate/Decode Files or Information
MalwareWellMess

WellMess can decode and decrypt data received from C2.

T1573.001
Symmetric Cryptography
MalwareWellMess

WellMess can encrypt HTTP POST data using RC6 and a dynamically generated AES key encrypted with a hard coded RSA public key.

T1573.002
Asymmetric Cryptography
MalwareWellMess

WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.