ATT&CKReferencesESET Sednit Part 1

ESET Sednit Part 1

ESET. (2016, October). En Route with Sednit - Part 1: Approaching the Target. Retrieved November 8, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareJHUHUGIT

JHUHUGIT tests if it can reach its C2 server by first attempting a direct connection, and if it fails, obtaining proxy settings and sending the connection through a proxy, and finally injecting code into a running browser if the proxy method fails.

T1027.013
Encrypted/Encoded File
MalwareJHUHUGIT

Many strings in JHUHUGIT are obfuscated with a XOR algorithm.

T1037.001
Logon Script (Windows)
MalwareJHUHUGIT

JHUHUGIT has registered a Windows shell script under the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

T1053.005
Scheduled Task
MalwareJHUHUGIT

JHUHUGIT has registered itself as a scheduled task to run each time the current user logs in.

T1057
Process Discovery
MalwareJHUHUGIT

JHUHUGIT obtains a list of running processes on the victim.

T1068
Exploitation for Privilege Escalation
MalwareJHUHUGIT

JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges.

T1070.004
File Deletion
MalwareJHUHUGIT

The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files.

T1071.001
Web Protocols
MalwareJHUHUGIT

JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS.

T1105
Ingress Tool Transfer
MalwareJHUHUGIT

JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine.

T1543.003
Windows Service
MalwareJHUHUGIT

JHUHUGIT has registered itself as a service to establish persistence.

T1546.015
Component Object Model Hijacking
GroupAPT28

APT28 has used COM hijacking for persistence by replacing the legitimate MMDeviceEnumerator object with a payload.

T1546.015
Component Object Model Hijacking
MalwareJHUHUGIT

JHUHUGIT has used COM hijacking to establish persistence by hijacking a class named MMDeviceEnumerator and also by registering the payload as a Shell Icon Overlay handler COM object ({3543619C-D563-43f7-95EA-4DA7E1CC396A}).

T1547.001
Registry Run Keys / Startup Folder
MalwareJHUHUGIT

JHUHUGIT has used a Registry Run key to establish persistence by executing JavaScript code within the rundll32.exe process.

T1680
Local Storage Discovery
MalwareJHUHUGIT

JHUHUGIT obtains a build identifier as well as victim hard drive information from Windows registry key HKLM\SYSTEM\CurrentControlSet\Services\Disk\Enum. Another JHUHUGIT variant gathers the victim storage volume serial number and the storage device name.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.