Ray, V. and Hayashi, K. (2019, February 1). Tracking OceanLotus’ new Downloader, KerrDown. Retrieved October 1, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareKerrdown | Kerrdown can encrypt, encode, and compress multiple layers of shellcode. |
| T1027.015 Compression |
MalwareKerrdown | Kerrdown can encrypt, encode, and compress multiple layers of shellcode. |
| T1059.005 Visual Basic |
MalwareKerrdown | Kerrdown can use a VBS base64 decoder function published by Motobit. |
| T1082 System Information Discovery |
MalwareKerrdown | Kerrdown has the ability to determine if the compromised host is running a 32 or 64 bit OS architecture. |
| T1105 Ingress Tool Transfer |
MalwareKerrdown | Kerrdown can download specific payloads to a compromised host based on OS architecture. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareKerrdown | Kerrdown can decode, decrypt, and decompress multiple layers of shellcode. |
| T1204.002 Malicious File |
MalwareKerrdown | Kerrdown has gained execution through victims opening malicious files. |
| T1574.001 DLL |
MalwareKerrdown | Kerrdown can use DLL side-loading to load malicious DLLs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.