ATT&CKReferencesUnit 42 MechaFlounder March 2019

Unit 42 MechaFlounder March 2019

Falcone, R. (2019, March 4). New Python-Based Payload MechaFlounder Used by Chafer. Retrieved May 27, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareMechaFlounder

MechaFlounder has the ability to identify the username and hostname on a compromised host.

T1036.005
Match Legitimate Resource Name or Location
MalwareMechaFlounder

MechaFlounder has been downloaded as a file named lsass.exe, which matches the legitimate Windows file.

T1041
Exfiltration Over C2 Channel
MalwareMechaFlounder

MechaFlounder has the ability to send the compromised user's account name and hostname within a URL to C2.

T1059.003
Windows Command Shell
MalwareMechaFlounder

MechaFlounder has the ability to run commands on a compromised host.

T1059.006
Python
MalwareMechaFlounder

MechaFlounder uses a python-based payload.

T1071.001
Web Protocols
MalwareMechaFlounder

MechaFlounder has the ability to use HTTP in communication with C2.

T1105
Ingress Tool Transfer
MalwareMechaFlounder

MechaFlounder has the ability to upload and download files to and from a compromised host.

T1132.001
Standard Encoding
MalwareMechaFlounder

MechaFlounder has the ability to use base16 encoded strings in C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.