ATT&CKReferencesCISA WellMail July 2020

CISA WellMail July 2020

CISA. (2020, July 16). MAR-10296782-3.v1 – WELLMAIL. Retrieved September 29, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareWellMail

WellMail can exfiltrate files from the victim machine.

T1016
System Network Configuration Discovery
MalwareWellMail

WellMail can identify the IP address of the victim system.

T1033
System Owner/User Discovery
MalwareWellMail

WellMail can identify the current username on the victim system.

T1095
Non-Application Layer Protocol
MalwareWellMail

WellMail can use TCP for C2 communications.

T1105
Ingress Tool Transfer
MalwareWellMail

WellMail can receive data and executable scripts from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareWellMail

WellMail can decompress scripts received from C2.

T1560
Archive Collected Data
MalwareWellMail

WellMail can archive files on the compromised host.

T1571
Non-Standard Port
MalwareWellMail

WellMail has been observed using TCP port 25, without using SMTP, to leverage an open port for secure command and control communications.

T1573.002
Asymmetric Cryptography
MalwareWellMail

WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.