ESET. (2016, October). En Route with Sednit - Part 1: Approaching the Target. Retrieved November 8, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareJHUHUGIT | JHUHUGIT tests if it can reach its C2 server by first attempting a direct connection, and if it fails, obtaining proxy settings and sending the connection through a proxy, and finally injecting code into a running browser if the proxy method fails. |
| T1027.013 Encrypted/Encoded File |
MalwareJHUHUGIT | Many strings in JHUHUGIT are obfuscated with a XOR algorithm. |
| T1037.001 Logon Script (Windows) |
MalwareJHUHUGIT | JHUHUGIT has registered a Windows shell script under the Registry key |
| T1053.005 Scheduled Task |
MalwareJHUHUGIT | JHUHUGIT has registered itself as a scheduled task to run each time the current user logs in. |
| T1057 Process Discovery |
MalwareJHUHUGIT | JHUHUGIT obtains a list of running processes on the victim. |
| T1068 Exploitation for Privilege Escalation |
MalwareJHUHUGIT | JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges. |
| T1070.004 File Deletion |
MalwareJHUHUGIT | The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files. |
| T1071.001 Web Protocols |
MalwareJHUHUGIT | JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS. |
| T1105 Ingress Tool Transfer |
MalwareJHUHUGIT | JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine. |
| T1543.003 Windows Service |
MalwareJHUHUGIT | JHUHUGIT has registered itself as a service to establish persistence. |
| T1546.015 Component Object Model Hijacking |
GroupAPT28 | APT28 has used COM hijacking for persistence by replacing the legitimate |
| T1546.015 Component Object Model Hijacking |
MalwareJHUHUGIT | JHUHUGIT has used COM hijacking to establish persistence by hijacking a class named MMDeviceEnumerator and also by registering the payload as a Shell Icon Overlay handler COM object ({3543619C-D563-43f7-95EA-4DA7E1CC396A}). |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareJHUHUGIT | JHUHUGIT has used a Registry Run key to establish persistence by executing JavaScript code within the rundll32.exe process. |
| T1680 Local Storage Discovery |
MalwareJHUHUGIT | JHUHUGIT obtains a build identifier as well as victim hard drive information from Windows registry key |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.