ATT&CKReferencesFidelis Turbo

Fidelis Turbo

Fidelis Cybersecurity. (2016, February 29). The Turbo Campaign, Featuring Derusbi for 64-bit Linux. Retrieved March 2, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareDerusbi

Derusbi uses a backup communication method with an HTTP beacon.

T1033
System Owner/User Discovery
MalwareDerusbi

A Linux version of Derusbi checks if the victim user ID is anything other than zero (normally used for root), and the malware will not execute if it does not have root privileges. Derusbi also gathers the username of the victim.

T1057
Process Discovery
MalwareDerusbi

Derusbi collects current and parent process IDs.

T1059.004
Unix Shell
MalwareDerusbi

Derusbi is capable of creating a remote Bash shell and executing commands.

T1070.004
File Deletion
MalwareDerusbi

Derusbi is capable of deleting files. It has been observed loading a Linux Kernel Module (LKM) and then deleting it from the hard disk as well as overwriting the data with null bytes.

T1070.006
Timestomp
MalwareDerusbi

The Derusbi malware supports timestomping.

T1082
System Information Discovery
MalwareDerusbi

Derusbi gathers the name of the local host, version of GNU Compiler Collection (GCC), and the system information about the CPU, machine, and operating system.

T1083
File and Directory Discovery
MalwareDerusbi

Derusbi is capable of obtaining directory, file, and drive listings.

T1095
Non-Application Layer Protocol
MalwareDerusbi

Derusbi binds to a raw socket on a random source port between 31800 and 31900 for C2.

T1571
Non-Standard Port
MalwareDerusbi

Derusbi has used unencrypted HTTP on port 443 for C2.

T1573.001
Symmetric Cryptography
MalwareDerusbi

Derusbi obfuscates C2 traffic with variable 4-byte XOR keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.