ATT&CKReferencesUnit42 Azorult Nov 2018

Unit42 Azorult Nov 2018

Yan, T., et al. (2018, November 21). New Wine in Old Bottle: New Azorult Variant Found in FindMyName Campaign using Fallout Exploit Kit. Retrieved November 29, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareAzorult

Azorult can check for installed software on the system under the Registry key Software\Microsoft\Windows\CurrentVersion\Uninstall.

T1016
System Network Configuration Discovery
MalwareAzorult

Azorult can collect host IP information from the victim’s machine.

T1033
System Owner/User Discovery
MalwareAzorult

Azorult can collect the username from the victim’s machine.

T1055.012
Process Hollowing
MalwareAzorult

Azorult can decrypt the payload into memory, create a new suspended process of itself, then inject a decrypted payload to the new process and resume new process execution.

T1057
Process Discovery
MalwareAzorult

Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot.

T1070.004
File Deletion
MalwareAzorult

Azorult can delete files from victim machines.

T1082
System Information Discovery
MalwareAzorult

Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language.

T1083
File and Directory Discovery
MalwareAzorult

Azorult can recursively search for files in folders and collects files from the desktop with certain extensions.

T1105
Ingress Tool Transfer
MalwareAzorult

Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes.

T1113
Screen Capture
MalwareAzorult

Azorult can capture screenshots of the victim’s machines.

T1124
System Time Discovery
MalwareAzorult

Azorult can collect the time zone information from the system.

T1134.002
Create Process with Token
MalwareAzorult

Azorult can call WTSQueryUserToken and CreateProcessAsUser to start a new process with local system privileges.

T1140
Deobfuscate/Decode Files or Information
MalwareAzorult

Azorult uses an XOR key to decrypt content and uses Base64 to decode the C2 address.

T1552.001
Credentials In Files
MalwareAzorult

Azorult can steal credentials in files belonging to common software such as Skype, Telegram, and Steam.

T1555.003
Credentials from Web Browsers
MalwareAzorult

Azorult can steal credentials from the victim's browser.

T1573.001
Symmetric Cryptography
MalwareAzorult

Azorult can encrypt C2 traffic using XOR.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.