Patil, S. (2018, June 26). Microsoft Office Vulnerabilities Used to Distribute FELIXROOT Backdoor in Recent Campaign. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareFELIXROOT | FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry. |
| T1027.013 Encrypted/Encoded File |
MalwareFELIXROOT | FELIXROOT encrypts strings in the backdoor using a custom XOR algorithm. |
| T1033 System Owner/User Discovery |
MalwareFELIXROOT | FELIXROOT collects the username from the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareFELIXROOT | FELIXROOT executes batch scripts on the victim’s machine, and can launch a reverse shell for command execution. |
| T1070.004 File Deletion |
MalwareFELIXROOT | FELIXROOT deletes the .LNK file from the startup directory as well as the dropper components. |
| T1071.001 Web Protocols |
MalwareFELIXROOT | FELIXROOT uses HTTP and HTTPS to communicate with the C2 server. |
| T1082 System Information Discovery |
MalwareFELIXROOT | FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type. |
| T1105 Ingress Tool Transfer |
MalwareFELIXROOT | FELIXROOT downloads and uploads files to and from the victim’s machine. |
| T1112 Modify Registry |
MalwareFELIXROOT | FELIXROOT deletes the Registry key |
| T1218.011 Rundll32 |
MalwareFELIXROOT | FELIXROOT uses Rundll32 for executing the dropper program. |
| T1560 Archive Collected Data |
MalwareFELIXROOT | FELIXROOT encrypts collected data with AES and Base64 and then sends it to the C2 server. |
| T1680 Local Storage Discovery |
MalwareFELIXROOT | FELIXROOT collects the victim’s volume serial number. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.