CISA. (2020, October 29). Malware Analysis Report (AR20-303B). Retrieved December 9, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareZebrocy | Zebrocy gets the username from the system. |
| T1041 Exfiltration Over C2 Channel |
MalwareZebrocy | Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests. |
| T1053.005 Scheduled Task |
MalwareZebrocy | Zebrocy has a command to create a scheduled task for persistence. |
| T1059.003 Windows Command Shell |
MalwareZebrocy | Zebrocy uses cmd.exe to execute commands on the system. |
| T1070.004 File Deletion |
MalwareZebrocy | Zebrocy has a command to delete files and directories. |
| T1082 System Information Discovery |
MalwareZebrocy | Zebrocy collects the OS version and computer name. Zebrocy also runs the |
| T1083 File and Directory Discovery |
MalwareZebrocy | Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the |
| T1113 Screen Capture |
MalwareZebrocy | A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format. |
| T1124 System Time Discovery |
MalwareZebrocy | Zebrocy gathers the current time zone and date information from the system. |
| T1560 Archive Collected Data |
MalwareZebrocy | Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration. |
| T1573.002 Asymmetric Cryptography |
MalwareZebrocy | Zebrocy uses SSL and AES ECB for encrypting C2 communications. |
| T1680 Local Storage Discovery |
MalwareZebrocy | Zebrocy collects the serial number for the storage volume C:\. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.