ATT&CKReferencesMalwarebytes Dyreza November 2015

Malwarebytes Dyreza November 2015

hasherezade. (2015, November 4). A Technical Look At Dyreza. Retrieved June 15, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareDyre

Dyre has the ability to identify running services on a compromised host.

T1016
System Network Configuration Discovery
MalwareDyre

Dyre has the ability to identify network settings on a compromised host.

T1027.002
Software Packing
MalwareDyre

Dyre has been delivered with encrypted resources and must be unpacked for execution.

T1033
System Owner/User Discovery
MalwareDyre

Dyre has the ability to identify the users on a compromised host.

T1041
Exfiltration Over C2 Channel
MalwareDyre

Dyre has the ability to send information staged on a compromised host externally to C2.

T1053.005
Scheduled Task
MalwareDyre

Dyre has the ability to achieve persistence by adding a new task in the task scheduler to run every minute.

T1055
Process Injection
MalwareDyre

Dyre has the ability to directly inject its code into the web browser process.

T1071.001
Web Protocols
MalwareDyre

Dyre uses HTTPS for C2 communications.

T1074.001
Local Data Staging
MalwareDyre

Dyre has the ability to create files in a TEMP folder to act as a database to store information.

T1082
System Information Discovery
MalwareDyre

Dyre has the ability to identify the computer name, OS version, and hardware configuration on a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareDyre

Dyre decrypts resources needed for targeting the victim.

T1497.001
System Checks
MalwareDyre

Dyre can detect sandbox analysis environments by inspecting the process list and Registry.

T1518
Software Discovery
MalwareDyre

Dyre has the ability to identify installed programs on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.