ATT&CKReferencesMicrosoft FinFisher March 2018

Microsoft FinFisher March 2018

Allievi, A.,Flori, E. (2018, March 01). FinFisher exposed: A researcher’s tale of defeating traps, tricks, and complex virtual machines. Retrieved July 9, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareFinFisher

FinFisher queries Registry values as part of its anti-sandbox checks.

T1027
Obfuscated Files or Information
MalwareFinFisher

FinFisher is heavily obfuscated in many ways, including through the use of spaghetti code in its functions in an effort to confuse disassembly programs. It also uses a custom XOR algorithm to obfuscate code.

T1027.016
Junk Code Insertion
MalwareFinFisher

FinFisher contains junk code in its functions in an effort to confuse disassembly programs.

T1036.005
Match Legitimate Resource Name or Location
MalwareFinFisher

FinFisher renames one of its .dll files to uxtheme.dll in an apparent attempt to masquerade as a legitimate file.

T1055.001
Dynamic-link Library Injection
MalwareFinFisher

FinFisher injects itself into various processes depending on whether it is low integrity or high integrity.

T1057
Process Discovery
MalwareFinFisher

FinFisher checks its parent process for indications that it is running in a sandbox setup.

T1082
System Information Discovery
MalwareFinFisher

FinFisher checks if the victim OS is 32 or 64-bit.

T1083
File and Directory Discovery
MalwareFinFisher

FinFisher enumerates directories and scans for certain files.

T1113
Screen Capture
MalwareFinFisher

FinFisher takes a screenshot of the screen and displays it on top of all other windows for few seconds in an apparent attempt to hide some messages showed by the system during the setup process.

T1134.001
Token Impersonation/Theft
MalwareFinFisher

FinFisher uses token manipulation with NtFilterToken as part of UAC bypass.

T1140
Deobfuscate/Decode Files or Information
MalwareFinFisher

FinFisher extracts and decrypts stage 3 malware, which is stored in encrypted resources.

T1497.001
System Checks
MalwareFinFisher

FinFisher obtains the hardware device list and checks if the MD5 of the vendor ID is equal to a predefined list in order to check for sandbox/virtualized environments.

T1542.003
Bootkit
MalwareFinFisher

Some FinFisher variants incorporate an MBR rootkit.

T1543.003
Windows Service
MalwareFinFisher

FinFisher creates a new Windows service with the malicious executable for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareFinFisher

FinFisher establishes persistence by creating the Registry key HKCU\Software\Microsoft\Windows\Run.

T1548.002
Bypass User Account Control
MalwareFinFisher

FinFisher performs UAC bypass.

T1574.001
DLL
MalwareFinFisher

FinFisher uses DLL side-loading to load malicious programs. A FinFisher variant also uses DLL search order hijacking.

T1685.005
Clear Windows Event Logs
MalwareFinFisher

FinFisher clears the system event logs using OpenEventLog/ClearEventLog APIs .

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.