ATT&CKReferencesCylance Shell Crew Feb 2017

Cylance Shell Crew Feb 2017

Cylance SPEAR Team. (2017, February 9). Shell Crew Variants Continue to Fly Under Big AV’s Radar. Retrieved February 15, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareStreamEx

StreamEx obfuscates some commands by using statically programmed fragments of strings when starting a DLL. It also uses a one-byte xor against 0x91 to encode configuration data.

T1057
Process Discovery
MalwareStreamEx

StreamEx has the ability to enumerate processes.

T1059.003
Windows Command Shell
MalwareStreamEx

StreamEx has the ability to remotely execute commands.

T1082
System Information Discovery
MalwareStreamEx

StreamEx has the ability to enumerate system information.

T1083
File and Directory Discovery
MalwareStreamEx

StreamEx has the ability to enumerate drive types.

T1112
Modify Registry
MalwareStreamEx

StreamEx has the ability to modify the Registry.

T1218.011
Rundll32
MalwareStreamEx

StreamEx uses rundll32 to call an exported function.

T1518.001
Security Software Discovery
MalwareStreamEx

StreamEx has the ability to scan for security tools such as firewalls and antivirus tools.

T1543.003
Windows Service
MalwareStreamEx

StreamEx establishes persistence by installing a new service pointing to its DLL and setting the service to auto-start.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.