ATT&CKReferencesUnit 42 KerrDown February 2019

Unit 42 KerrDown February 2019

Ray, V. and Hayashi, K. (2019, February 1). Tracking OceanLotus’ new Downloader, KerrDown. Retrieved October 1, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareKerrdown

Kerrdown can encrypt, encode, and compress multiple layers of shellcode.

T1027.015
Compression
MalwareKerrdown

Kerrdown can encrypt, encode, and compress multiple layers of shellcode.

T1059.005
Visual Basic
MalwareKerrdown

Kerrdown can use a VBS base64 decoder function published by Motobit.

T1082
System Information Discovery
MalwareKerrdown

Kerrdown has the ability to determine if the compromised host is running a 32 or 64 bit OS architecture.

T1105
Ingress Tool Transfer
MalwareKerrdown

Kerrdown can download specific payloads to a compromised host based on OS architecture.

T1140
Deobfuscate/Decode Files or Information
MalwareKerrdown

Kerrdown can decode, decrypt, and decompress multiple layers of shellcode.

T1204.002
Malicious File
MalwareKerrdown

Kerrdown has gained execution through victims opening malicious files.

T1574.001
DLL
MalwareKerrdown

Kerrdown can use DLL side-loading to load malicious DLLs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.