Proofpoint. (2018, July 30). New version of AZORult stealer improves loading features, spreads alongside ransomware in new campaign. Retrieved November 29, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareAzorult | Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot. |
| T1082 System Information Discovery |
MalwareAzorult | Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language. |
| T1105 Ingress Tool Transfer |
MalwareAzorult | Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes. |
| T1124 System Time Discovery |
MalwareAzorult | Azorult can collect the time zone information from the system. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAzorult | Azorult uses an XOR key to decrypt content and uses Base64 to decode the C2 address. |
| T1573.001 Symmetric Cryptography |
MalwareAzorult | Azorult can encrypt C2 traffic using XOR. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.