ATT&CKReferencesCyphort EvilBunny Dec 2014

Cyphort EvilBunny Dec 2014

Marschalek, M.. (2014, December 16). EvilBunny: Malware Instrumented By Lua. Retrieved June 28, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareEvilBunny

EvilBunny has used WMI to gather information about the system.

T1053.005
Scheduled Task
MalwareEvilBunny

EvilBunny has executed commands via scheduled tasks.

T1057
Process Discovery
MalwareEvilBunny

EvilBunny has used EnumProcesses() to identify how many process are running in the environment.

T1059.003
Windows Command Shell
MalwareEvilBunny

EvilBunny has an integrated scripting engine to download and execute Lua scripts.

T1070.004
File Deletion
MalwareEvilBunny

EvilBunny has deleted the initial dropper after running through the environment checks.

T1071.001
Web Protocols
MalwareEvilBunny

EvilBunny has executed C2 commands directly via HTTP.

T1105
Ingress Tool Transfer
MalwareEvilBunny

EvilBunny has downloaded additional Lua scripts from the C2.

T1106
Native API
MalwareEvilBunny

EvilBunny has used various API calls as part of its checks to see if the malware is running in a sandbox.

T1124
System Time Discovery
MalwareEvilBunny

EvilBunny has used the API calls NtQuerySystemTime, GetSystemTimeAsFileTime, and GetTickCount to gather time metrics as part of its checks to see if the malware is running in a sandbox.

T1203
Exploitation for Client Execution
MalwareEvilBunny

EvilBunny has exploited CVE-2011-4369, a vulnerability in the PRC component in Adobe Reader.

T1497.001
System Checks
MalwareEvilBunny

EvilBunny's dropper has checked the number of processes and the length and strings of its own file name to identify if the malware is in a sandbox environment.

T1497.003
Time Based Checks
MalwareEvilBunny

EvilBunny has used time measurements from 3 different APIs before and after performing sleep operations to check and abort if the malware is running in a sandbox.

T1518.001
Security Software Discovery
MalwareEvilBunny

EvilBunny has been observed querying installed antivirus software.

T1547.001
Registry Run Keys / Startup Folder
MalwareEvilBunny

EvilBunny has created Registry keys for persistence in [HKLM|HKCU]\…\CurrentVersion\Run.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.