ATT&CKReferencesMedium Metamorfo Apr 2020

Medium Metamorfo Apr 2020

Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareMetamorfo

Metamorfo has encrypted payloads and strings.

T1036.005
Match Legitimate Resource Name or Location
MalwareMetamorfo

Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example.

T1055.001
Dynamic-link Library Injection
MalwareMetamorfo

Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe).

T1057
Process Discovery
MalwareMetamorfo

Metamorfo has performed process name checks and has monitored applications.

T1059.003
Windows Command Shell
MalwareMetamorfo

Metamorfo has used cmd.exe /c to execute files.

T1059.007
JavaScript
MalwareMetamorfo

Metamorfo includes payloads written in JavaScript.

T1070.004
File Deletion
MalwareMetamorfo

Metamorfo has deleted itself from the system after execution.

T1071.001
Web Protocols
MalwareMetamorfo

Metamorfo has used HTTP for C2.

T1083
File and Directory Discovery
MalwareMetamorfo

Metamorfo has searched the Program Files directories for specific folders and has searched for strings related to its mutexes.

T1102.003
One-Way Communication
MalwareMetamorfo

Metamorfo has downloaded a zip file for execution on the system.

T1105
Ingress Tool Transfer
MalwareMetamorfo

Metamorfo has used MSI files to download additional files to execute.

T1106
Native API
MalwareMetamorfo

Metamorfo has used native WINAPI calls.

T1112
Modify Registry
MalwareMetamorfo

Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key.

T1124
System Time Discovery
MalwareMetamorfo

Metamorfo uses JavaScript to get the system time.

T1140
Deobfuscate/Decode Files or Information
MalwareMetamorfo

Upon execution, Metamorfo has unzipped itself after being downloaded to the system and has performed string decryption.

T1497
Virtualization/Sandbox Evasion
MalwareMetamorfo

Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution.

T1547.001
Registry Run Keys / Startup Folder
MalwareMetamorfo

Metamorfo has configured persistence to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run, Spotify =% APPDATA%\Spotify\Spotify.exe and used .LNK files in the startup folder to achieve persistence.

T1553.002
Code Signing
MalwareMetamorfo

Metamorfo has digitally signed executables using AVAST Software certificates.

T1564.003
Hidden Window
MalwareMetamorfo

Metamorfo has hidden its GUI using the ShowWindow() WINAPI call.

T1573.002
Asymmetric Cryptography
MalwareMetamorfo

Metamorfo's C2 communication has been encrypted using OpenSSL.

T1574.001
DLL
MalwareMetamorfo

Metamorfo has side-loaded its malicious DLL file.

T1685
Disable or Modify Tools
MalwareMetamorfo

Metamorfo has a function to kill processes associated with defenses and can prevent certain processes from launching.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.