Hsu, K. et al. (2020, June 24). Lucifer: New Cryptojacking and DDoS Hybrid Malware Exploiting High and Critical Vulnerabilities to Infect Windows Devices. Retrieved November 16, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareLucifer | Lucifer can check for existing stratum cryptomining information in |
| T1016 System Network Configuration Discovery |
MalwareLucifer | Lucifer can collect the IP address of a compromised host. |
| T1021.002 SMB/Windows Admin Shares |
MalwareLucifer | Lucifer can infect victims by brute forcing SMB. |
| T1027.002 Software Packing |
MalwareLucifer | Lucifer has used UPX packed binaries. |
| T1033 System Owner/User Discovery |
MalwareLucifer | Lucifer has the ability to identify the username on a compromised host. |
| T1046 Network Service Discovery |
MalwareLucifer | Lucifer can scan for open ports including TCP ports 135 and 1433. |
| T1047 Windows Management Instrumentation |
MalwareLucifer | Lucifer can use WMI to log into remote machines for propagation. |
| T1049 System Network Connections Discovery |
MalwareLucifer | Lucifer can identify the IP and port numbers for all remote connections from the compromised host. |
| T1053.005 Scheduled Task |
MalwareLucifer | Lucifer has established persistence by creating the following scheduled task |
| T1057 Process Discovery |
MalwareLucifer | Lucifer can identify the process that owns remote connections. |
| T1059.003 Windows Command Shell |
MalwareLucifer | Lucifer can issue shell commands to download and execute additional payloads. |
| T1071 Application Layer Protocol |
MalwareLucifer | Lucifer can use the Stratum protocol on port 10001 for communication between the cryptojacking bot and the mining server. |
| T1082 System Information Discovery |
MalwareLucifer | Lucifer can collect the computer name, system architecture, default language, and processor frequency of a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareLucifer | Lucifer can download and execute a replica of itself using certutil. |
| T1110.001 Password Guessing |
MalwareLucifer | Lucifer has attempted to brute force TCP ports 135 (RPC) and 1433 (MSSQL) with the default username or list of usernames and passwords. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLucifer | Lucifer can decrypt its C2 address upon execution. |
| T1210 Exploitation of Remote Services |
MalwareLucifer | Lucifer can exploit multiple vulnerabilities including EternalBlue (CVE-2017-0144) and EternalRomance (CVE-2017-0144). |
| T1496.001 Compute Hijacking |
MalwareLucifer | Lucifer can use system resources to mine cryptocurrency, dropping XMRig to mine Monero. |
| T1497.001 System Checks |
MalwareLucifer | Lucifer can check for specific usernames, computer names, device drivers, DLL's, and virtual devices associated with sandboxed environments and can enter an infinite loop and stop itself if any are detected. |
| T1498 Network Denial of Service |
MalwareLucifer | Lucifer can execute TCP, UDP, and HTTP denial of service (DoS) attacks. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareLucifer | Lucifer can persist by setting Registry key values |
| T1570 Lateral Tool Transfer |
MalwareLucifer | Lucifer can use certutil for propagation on Windows hosts within intranets. |
| T1573.001 Symmetric Cryptography |
MalwareLucifer | Lucifer can perform a decremental-xor encryption on the initial C2 request before sending it over the wire. |
| T1685.005 Clear Windows Event Logs |
MalwareLucifer | Lucifer can clear and remove event logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.