ATT&CKReferencesFireEye FELIXROOT July 2018

FireEye FELIXROOT July 2018

Patil, S. (2018, June 26). Microsoft Office Vulnerabilities Used to Distribute FELIXROOT Backdoor in Recent Campaign. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareFELIXROOT

FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry.

T1027.013
Encrypted/Encoded File
MalwareFELIXROOT

FELIXROOT encrypts strings in the backdoor using a custom XOR algorithm.

T1033
System Owner/User Discovery
MalwareFELIXROOT

FELIXROOT collects the username from the victim’s machine.

T1059.003
Windows Command Shell
MalwareFELIXROOT

FELIXROOT executes batch scripts on the victim’s machine, and can launch a reverse shell for command execution.

T1070.004
File Deletion
MalwareFELIXROOT

FELIXROOT deletes the .LNK file from the startup directory as well as the dropper components.

T1071.001
Web Protocols
MalwareFELIXROOT

FELIXROOT uses HTTP and HTTPS to communicate with the C2 server.

T1082
System Information Discovery
MalwareFELIXROOT

FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type.

T1105
Ingress Tool Transfer
MalwareFELIXROOT

FELIXROOT downloads and uploads files to and from the victim’s machine.

T1112
Modify Registry
MalwareFELIXROOT

FELIXROOT deletes the Registry key HKCU\Software\Classes\Applications\rundll32.exe\shell\open.

T1218.011
Rundll32
MalwareFELIXROOT

FELIXROOT uses Rundll32 for executing the dropper program.

T1560
Archive Collected Data
MalwareFELIXROOT

FELIXROOT encrypts collected data with AES and Base64 and then sends it to the C2 server.

T1680
Local Storage Discovery
MalwareFELIXROOT

FELIXROOT collects the victim’s volume serial number.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.