ATT&CKReferencesESET Hermetic Wizard March 2022

ESET Hermetic Wizard March 2022

ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareHermeticWizard

HermeticWizard can find machines on the local network by gathering known local IP addresses through `DNSGetCacheDataTable`, `GetIpNetTable`,`WNetOpenEnumW(RESOURCE_GLOBALNET, RESOURCETYPE_ANY)`,`NetServerEnum`,`GetTcpTable`, and `GetAdaptersAddresses.`

T1021.002
SMB/Windows Admin Shares
MalwareHermeticWizard

HermeticWizard can use a list of hardcoded credentials to to authenticate via NTLMSSP to the SMB shares on remote systems.

T1027.013
Encrypted/Encoded File
MalwareHermeticWizard

HermeticWizard has the ability to encrypt PE files with a reverse XOR loop.

T1036.005
Match Legitimate Resource Name or Location
MalwareHermeticWiper

HermeticWiper has used the name `postgressql.exe` to mask a malicious payload.

T1036.005
Match Legitimate Resource Name or Location
MalwareHermeticWizard

HermeticWizard has been named `exec_32.dll` to mimic a legitimate MS Outlook .dll.

T1046
Network Service Discovery
MalwareHermeticWizard

HermeticWizard has the ability to scan ports on a compromised network.

T1047
Windows Management Instrumentation
MalwareHermeticWizard

HermeticWizard can use WMI to create a new process on a remote machine via `C:\windows\system32\cmd.exe /c start C:\windows\system32\\regsvr32.exe /s /iC:\windows\<filename>.dll`.

T1059.003
Windows Command Shell
MalwareHermeticWizard

HermeticWizard can use `cmd.exe` for execution on compromised hosts.

T1059.003
Windows Command Shell
MalwareHermeticWiper

HermeticWiper can use `cmd.exe /Q/c move CSIDL_SYSTEM_DRIVE\temp\sys.tmp1 CSIDL_WINDOWS\policydefinitions\postgresql.exe 1> \\127.0.0.1\ADMIN$\_1636727589.6007507 2>&1` to deploy on an infected system.

T1070
Indicator Removal
MalwareHermeticWiper

HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services.

T1070.004
File Deletion
MalwareHermeticWiper

HermeticWiper has the ability to overwrite its own file with random bites.

T1082
System Information Discovery
MalwareHermeticWiper

HermeticWiper can determine the OS version and bitness on a targeted host.

T1106
Native API
MalwareHermeticWizard

HermeticWizard can connect to remote shares using `WNetAddConnection2W`.

T1106
Native API
MalwareHermeticWiper

HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data.

T1110.001
Password Guessing
MalwareHermeticWizard

HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares.

T1218.010
Regsvr32
MalwareHermeticWizard

HermeticWizard has used `regsvr32.exe /s /i` to execute malicious payloads.

T1218.011
Rundll32
MalwareHermeticWizard

HermeticWizard has the ability to create a new process using `rundll32`.

T1484.001
Group Policy Modification
MalwareHermeticWiper

HermeticWiper has the ability to deploy through an infected system's default domain policy.

T1485
Data Destruction
MalwareHermeticWiper

HermeticWiper can recursively wipe folders and files in `Windows`, `Program Files`, `Program Files(x86)`, `PerfLogs`, `Boot, System`, `Volume Information`, and `AppData` folders using `FSCTL_MOVE_FILE`. HermeticWiper can also overwrite symbolic links and big files in `My Documents` and on the Desktop with random bytes.

T1490
Inhibit System Recovery
MalwareHermeticWiper

HermeticWiper can disable the VSS service on a compromised host using the service control manager.

T1553.002
Code Signing
MalwareHermeticWizard

HermeticWizard has been signed by valid certificates assigned to Hermetica Digital.

T1559.001
Component Object Model
MalwareHermeticWizard

HermeticWizard can execute files on remote machines using DCOM.

T1569.002
Service Execution
MalwareHermeticWizard

HermeticWizard can use `OpenRemoteServiceManager` to create a service.

T1570
Lateral Tool Transfer
MalwareHermeticWizard

HermeticWizard can copy files to other machines on a compromised network.

T1680
Local Storage Discovery
MalwareHermeticWiper

HermeticWiper can enumerate physical drives on a targeted host.

T1685.005
Clear Windows Event Logs
MalwareHermeticWiper

HermeticWiper can overwrite the `C:\Windows\System32\winevt\Logs` file on a targeted system.

T1685.005
Clear Windows Event Logs
MalwareHermeticWizard

HermeticWizard has the ability to use `wevtutil cl system` to clear event logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.