ATT&CKReferencesJPCERT ChChes Feb 2017

JPCERT ChChes Feb 2017

Nakamura, Y.. (2017, February 17). ChChes - Malware that Communicates with C&C Servers Using Cookie Headers. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareChChes

ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header.

T1105
Ingress Tool Transfer
MalwareChChes

ChChes is capable of downloading files, including additional modules.

T1132.001
Standard Encoding
MalwareChChes

ChChes can encode C2 data with a custom technique that utilizes Base64.

T1553.002
Code Signing
MalwareChChes

ChChes samples were digitally signed with a certificate originally used by Hacking Team that was later leaked and subsequently revoked.

T1573.001
Symmetric Cryptography
MalwareChChes

ChChes can encrypt C2 traffic with AES or RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.