Marschalek, M.. (2014, December 16). EvilBunny: Malware Instrumented By Lua. Retrieved June 28, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareEvilBunny | EvilBunny has used WMI to gather information about the system. |
| T1053.005 Scheduled Task |
MalwareEvilBunny | EvilBunny has executed commands via scheduled tasks. |
| T1057 Process Discovery |
MalwareEvilBunny | EvilBunny has used EnumProcesses() to identify how many process are running in the environment. |
| T1059.003 Windows Command Shell |
MalwareEvilBunny | EvilBunny has an integrated scripting engine to download and execute Lua scripts. |
| T1070.004 File Deletion |
MalwareEvilBunny | EvilBunny has deleted the initial dropper after running through the environment checks. |
| T1071.001 Web Protocols |
MalwareEvilBunny | EvilBunny has executed C2 commands directly via HTTP. |
| T1105 Ingress Tool Transfer |
MalwareEvilBunny | EvilBunny has downloaded additional Lua scripts from the C2. |
| T1106 Native API |
MalwareEvilBunny | EvilBunny has used various API calls as part of its checks to see if the malware is running in a sandbox. |
| T1124 System Time Discovery |
MalwareEvilBunny | EvilBunny has used the API calls NtQuerySystemTime, GetSystemTimeAsFileTime, and GetTickCount to gather time metrics as part of its checks to see if the malware is running in a sandbox. |
| T1203 Exploitation for Client Execution |
MalwareEvilBunny | EvilBunny has exploited CVE-2011-4369, a vulnerability in the PRC component in Adobe Reader. |
| T1497.001 System Checks |
MalwareEvilBunny | EvilBunny's dropper has checked the number of processes and the length and strings of its own file name to identify if the malware is in a sandbox environment. |
| T1497.003 Time Based Checks |
MalwareEvilBunny | EvilBunny has used time measurements from 3 different APIs before and after performing sleep operations to check and abort if the malware is running in a sandbox. |
| T1518.001 Security Software Discovery |
MalwareEvilBunny | EvilBunny has been observed querying installed antivirus software. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEvilBunny | EvilBunny has created Registry keys for persistence in |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.