ATT&CKReferencesCheckPoint SpeakUp Feb 2019

CheckPoint SpeakUp Feb 2019

Check Point Research. (2019, February 4). SpeakUp: A New Undetected Backdoor Linux Trojan. Retrieved April 17, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareSpeakUp

SpeakUp uses the ifconfig -a command.

T1027.013
Encrypted/Encoded File
MalwareSpeakUp

SpeakUp encodes its second-stage payload with Base64.

T1033
System Owner/User Discovery
MalwareSpeakUp

SpeakUp uses the whoami command.

T1046
Network Service Discovery
MalwareSpeakUp

SpeakUp checks for availability of specific ports on servers.

T1049
System Network Connections Discovery
MalwareSpeakUp

SpeakUp uses the arp -a command.

T1053.003
Cron
MalwareSpeakUp

SpeakUp uses cron tasks to ensure persistence.

T1059
Command and Scripting Interpreter
MalwareSpeakUp

SpeakUp uses Perl scripts.

T1059.006
Python
MalwareSpeakUp

SpeakUp uses Python scripts.

T1070.004
File Deletion
MalwareSpeakUp

SpeakUp deletes files to remove evidence on the machine.

T1071.001
Web Protocols
MalwareSpeakUp

SpeakUp uses POST and GET requests over HTTP to communicate with its main C&C server.

T1082
System Information Discovery
MalwareSpeakUp

SpeakUp uses the cat /proc/cpuinfo | grep -c “cpu family” 2>&1 command to gather system information.

T1105
Ingress Tool Transfer
MalwareSpeakUp

SpeakUp downloads and executes additional files from a remote server.

T1110.001
Password Guessing
MalwareSpeakUp

SpeakUp can perform brute forcing using a pre-defined list of usernames and passwords in an attempt to log in to administrative panels.

T1132.001
Standard Encoding
MalwareSpeakUp

SpeakUp encodes C&C communication using Base64.

T1203
Exploitation for Client Execution
MalwareSpeakUp

SpeakUp attempts to exploit the following vulnerabilities in order to execute its malicious script: CVE-2012-0874, CVE-2010-1871, CVE-2017-10271, CVE-2018-2894, CVE-2016-3088, JBoss AS 3/4/5/6, and the Hadoop YARN ResourceManager.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.