Yan, T., et al. (2018, November 21). New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit. Retrieved November 29, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareAzorult | Azorult can check for installed software on the system under the Registry key |
| T1016 System Network Configuration Discovery |
MalwareAzorult | Azorult can collect host IP information from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareAzorult | Azorult can collect the username from the victim’s machine. |
| T1055.012 Process Hollowing |
MalwareAzorult | Azorult can decrypt the payload into memory, create a new suspended process of itself, then inject a decrypted payload to the new process and resume new process execution. |
| T1057 Process Discovery |
MalwareAzorult | Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot. |
| T1070.004 File Deletion |
MalwareAzorult | Azorult can delete files from victim machines. |
| T1082 System Information Discovery |
MalwareAzorult | Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language. |
| T1083 File and Directory Discovery |
MalwareAzorult | Azorult can recursively search for files in folders and collects files from the desktop with certain extensions. |
| T1105 Ingress Tool Transfer |
MalwareAzorult | Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes. |
| T1113 Screen Capture |
MalwareAzorult | Azorult can capture screenshots of the victim’s machines. |
| T1124 System Time Discovery |
MalwareAzorult | Azorult can collect the time zone information from the system. |
| T1134.002 Create Process with Token |
MalwareAzorult | Azorult can call WTSQueryUserToken and CreateProcessAsUser to start a new process with local system privileges. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAzorult | Azorult uses an XOR key to decrypt content and uses Base64 to decode the C2 address. |
| T1552.001 Credentials In Files |
MalwareAzorult | Azorult can steal credentials in files belonging to common software such as Skype, Telegram, and Steam. |
| T1555.003 Credentials from Web Browsers |
MalwareAzorult | Azorult can steal credentials from the victim's browser. |
| T1573.001 Symmetric Cryptography |
MalwareAzorult | Azorult can encrypt C2 traffic using XOR. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.