Salem, E. et al. (2020, May 28). VALAK: MORE THAN MEETS THE EYE . Retrieved June 19, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareValak | Valak has the ability to identify the domain and the MAC and IP addresses of an infected machine. |
| T1027 Obfuscated Files or Information |
MalwareValak | Valak has the ability to base64 encode and XOR encrypt strings. |
| T1027.011 Fileless Storage |
MalwareValak | Valak has the ability to store information regarding the C2 server and downloads in the Registry key |
| T1033 System Owner/User Discovery |
MalwareValak | Valak can gather information regarding the user. |
| T1041 Exfiltration Over C2 Channel |
MalwareValak | Valak has the ability to exfiltrate data over the C2 channel. |
| T1053.005 Scheduled Task |
MalwareValak | Valak has used scheduled tasks to execute additional payloads and to gain persistence on a compromised host. |
| T1057 Process Discovery |
MalwareValak | Valak has the ability to enumerate running processes on a compromised host. |
| T1059.001 PowerShell |
MalwareValak | Valak has used PowerShell to download additional modules. |
| T1059.007 JavaScript |
MalwareValak | Valak can execute JavaScript containing configuration data for establishing persistence. |
| T1071.001 Web Protocols |
MalwareValak | Valak has used HTTP in communications with C2. |
| T1082 System Information Discovery |
MalwareValak | Valak can determine the Windows version and computer name on a compromised host. |
| T1087.001 Local Account |
MalwareValak | Valak has the ability to enumerate local admin accounts. |
| T1087.002 Domain Account |
MalwareValak | Valak has the ability to enumerate domain admin accounts. |
| T1105 Ingress Tool Transfer |
MalwareValak | Valak has downloaded a variety of modules and payloads to the compromised host, including IcedID and NetSupport Manager RAT-based malware. |
| T1112 Modify Registry |
MalwareValak | Valak has the ability to modify the Registry key |
| T1113 Screen Capture |
MalwareValak | Valak has the ability to take screenshots on a compromised host. |
| T1114.002 Remote Email Collection |
MalwareValak | Valak can collect sensitive mailing information from Exchange servers, including credentials and the domain certificate of an enterprise. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareValak | Valak has the ability to decode and decrypt downloaded files. |
| T1204.002 Malicious File |
MalwareValak | Valak has been executed via Microsoft Word documents containing malicious macros. |
| T1218.010 Regsvr32 |
MalwareValak | Valak has used |
| T1518.001 Security Software Discovery |
MalwareValak | Valak can determine if a compromised host has security products installed. |
| T1564.004 NTFS File Attributes |
MalwareValak | Valak has the ability save and execute files as alternate data streams (ADS). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.