ATT&CKReferencesCISA Zebrocy Oct 2020

CISA Zebrocy Oct 2020

CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareZebrocy

Zebrocy gets the username from the system.

T1041
Exfiltration Over C2 Channel
MalwareZebrocy

Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests.

T1053.005
Scheduled Task
MalwareZebrocy

Zebrocy has a command to create a scheduled task for persistence.

T1059.003
Windows Command Shell
MalwareZebrocy

Zebrocy uses cmd.exe to execute commands on the system.

T1070.004
File Deletion
MalwareZebrocy

Zebrocy has a command to delete files and directories.

T1082
System Information Discovery
MalwareZebrocy

Zebrocy collects the OS version and computer name. Zebrocy also runs the systeminfo command to gather system information.

T1083
File and Directory Discovery
MalwareZebrocy

Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the echo %APPDATA% command to list the contents of the directory. Zebrocy can obtain the current execution path as well as perform drive enumeration.

T1113
Screen Capture
MalwareZebrocy

A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format.

T1124
System Time Discovery
MalwareZebrocy

Zebrocy gathers the current time zone and date information from the system.

T1560
Archive Collected Data
MalwareZebrocy

Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration.

T1573.002
Asymmetric Cryptography
MalwareZebrocy

Zebrocy uses SSL and AES ECB for encrypting C2 communications.

T1680
Local Storage Discovery
MalwareZebrocy

Zebrocy collects the serial number for the storage volume C:\.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.