ATT&CKReferencesHP SVCReady Jun 2022

HP SVCReady Jun 2022

Schlapfer, Patrick. (2022, June 6). A New Loader Gets Ready. Retrieved December 13, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSVCReady

SVCReady can collect data from an infected host.

T1012
Query Registry
MalwareSVCReady

SVCReady can search for the `HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System` Registry key to gather system information.

T1027
Obfuscated Files or Information
MalwareSVCReady

SVCReady can encrypt victim data with an RC4 cipher.

T1033
System Owner/User Discovery
MalwareSVCReady

SVCReady can collect the username from an infected host.

T1036.004
Masquerade Task or Service
MalwareSVCReady

SVCReady has named a task `RecoveryExTask` as part of its persistence activity.

T1041
Exfiltration Over C2 Channel
MalwareSVCReady

SVCReady can send collected data in JSON format to its C2 server.

T1047
Windows Management Instrumentation
MalwareSVCReady

SVCReady can use `WMI` queries to detect the presence of a virtual machine environment.

T1053.005
Scheduled Task
MalwareSVCReady

SVCReady can create a scheduled task named `RecoveryExTask` to gain persistence.

T1057
Process Discovery
MalwareSVCReady

SVCReady can collect a list of running processes from an infected host.

T1059.005
Visual Basic
MalwareSVCReady

SVCReady has used VBA macros to execute shellcode.

T1071.001
Web Protocols
MalwareSVCReady

SVCReady can communicate with its C2 servers via HTTP.

T1082
System Information Discovery
MalwareSVCReady

SVCReady has the ability to collect information such as computer name, computer manufacturer, BIOS, operating system, and firmware, including through the use of `systeminfo.exe`.

T1105
Ingress Tool Transfer
MalwareSVCReady

SVCReady has the ability to download additional tools such as the RedLine Stealer to an infected host.

T1106
Native API
MalwareSVCReady

SVCReady can use Windows API calls to gather information from an infected host.

T1113
Screen Capture
MalwareSVCReady

SVCReady can take a screenshot from an infected host.

T1120
Peripheral Device Discovery
MalwareSVCReady

SVCReady can check for the number of devices plugged into an infected host.

T1124
System Time Discovery
MalwareSVCReady

SVCReady can collect time zone information.

T1204.002
Malicious File
MalwareSVCReady

SVCReady has relied on users clicking a malicious attachment delivered through spearphishing.

T1218.011
Rundll32
MalwareSVCReady

SVCReady has used `rundll32.exe` for execution.

T1497.001
System Checks
MalwareSVCReady

SVCReady has the ability to determine if its runtime environment is virtualized.

T1497.003
Time Based Checks
MalwareSVCReady

SVCReady can enter a sleep stage for 30 minutes to evade detection.

T1518
Software Discovery
MalwareSVCReady

SVCReady can collect a list of installed software from an infected host.

T1546.015
Component Object Model Hijacking
MalwareSVCReady

SVCReady has created the `HKEY_CURRENT_USER\Software\Classes\CLSID\{E6D34FFC-AD32-4d6a-934C-D387FA873A19}` Registry key for persistence.

T1566.001
Spearphishing Attachment
MalwareSVCReady

SVCReady has been distributed via spearphishing campaigns containing malicious Mircrosoft Word documents.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.