Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareMetamorfo | Metamorfo has encrypted payloads and strings. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareMetamorfo | Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example. |
| T1055.001 Dynamic-link Library Injection |
MalwareMetamorfo | Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe). |
| T1057 Process Discovery |
MalwareMetamorfo | Metamorfo has performed process name checks and has monitored applications. |
| T1059.003 Windows Command Shell |
MalwareMetamorfo | Metamorfo has used |
| T1059.007 JavaScript |
MalwareMetamorfo | Metamorfo includes payloads written in JavaScript. |
| T1070.004 File Deletion |
MalwareMetamorfo | Metamorfo has deleted itself from the system after execution. |
| T1071.001 Web Protocols |
MalwareMetamorfo | Metamorfo has used HTTP for C2. |
| T1083 File and Directory Discovery |
MalwareMetamorfo | Metamorfo has searched the Program Files directories for specific folders and has searched for strings related to its mutexes. |
| T1102.003 One-Way Communication |
MalwareMetamorfo | Metamorfo has downloaded a zip file for execution on the system. |
| T1105 Ingress Tool Transfer |
MalwareMetamorfo | Metamorfo has used MSI files to download additional files to execute. |
| T1106 Native API |
MalwareMetamorfo | Metamorfo has used native WINAPI calls. |
| T1112 Modify Registry |
MalwareMetamorfo | Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key. |
| T1124 System Time Discovery |
MalwareMetamorfo | Metamorfo uses JavaScript to get the system time. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMetamorfo | Upon execution, Metamorfo has unzipped itself after being downloaded to the system and has performed string decryption. |
| T1497 Virtualization/Sandbox Evasion |
MalwareMetamorfo | Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMetamorfo | Metamorfo has configured persistence to the Registry key |
| T1553.002 Code Signing |
MalwareMetamorfo | Metamorfo has digitally signed executables using AVAST Software certificates. |
| T1564.003 Hidden Window |
MalwareMetamorfo | Metamorfo has hidden its GUI using the ShowWindow() WINAPI call. |
| T1573.002 Asymmetric Cryptography |
MalwareMetamorfo | Metamorfo's C2 communication has been encrypted using OpenSSL. |
| T1574.001 DLL |
MalwareMetamorfo | Metamorfo has side-loaded its malicious DLL file. |
| T1685 Disable or Modify Tools |
MalwareMetamorfo | Metamorfo has a function to kill processes associated with defenses and can prevent certain processes from launching. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.