ATT&CKReferencesMorphisec Snip3 May 2021

Morphisec Snip3 May 2021

Lorber, N. (2021, May 7). Revealing the Snip3 Crypter, a Highly Evasive RAT Loader. Retrieved September 13, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareSnip3

Snip3 has the ability to obfuscate strings using XOR encryption.

T1027.001
Binary Padding
MalwareSnip3

Snip3 can obfuscate strings using junk Chinese characters.

T1047
Windows Management Instrumentation
MalwareSnip3

Snip3 can query the WMI class `Win32_ComputerSystem` to gather information.

T1055.012
Process Hollowing
MalwareSnip3

Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process.

T1059.001
PowerShell
MalwareSnip3

Snip3 can use a PowerShell script for second-stage execution.

T1059.005
Visual Basic
MalwareSnip3

Snip3 can use visual basic scripts for first-stage execution.

T1082
System Information Discovery
MalwareSnip3

Snip3 has the ability to query `Win32_ComputerSystem` for system information.

T1102
Web Service
MalwareSnip3

Snip3 can download additional payloads from web services including Pastebin and top4top.

T1104
Multi-Stage Channels
MalwareSnip3

Snip3 can download and execute additional payloads and modules over separate communication channels.

T1105
Ingress Tool Transfer
MalwareSnip3

Snip3 can download additional payloads to compromised systems.

T1140
Deobfuscate/Decode Files or Information
MalwareSnip3

Snip3 can decode its second-stage PowerShell script prior to execution.

T1204.002
Malicious File
MalwareSnip3

Snip3 can gain execution through the download of visual basic files.

T1497.001
System Checks
MalwareSnip3

Snip3 has the ability to detect Windows Sandbox, VMWare, or VirtualBox by querying `Win32_ComputerSystem` to extract the `Manufacturer` string.

T1497.003
Time Based Checks
MalwareSnip3

Snip3 can execute `WScript.Sleep` to delay execution of its second stage.

T1564.003
Hidden Window
MalwareSnip3

Snip3 can execute PowerShell scripts in a hidden window.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.