ESET. (2022, March 1). IsaacWiper and HermeticWizard: New wiper and worm targetingUkraine. Retrieved April 10, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
MalwareHermeticWizard | HermeticWizard can find machines on the local network by gathering known local IP addresses through `DNSGetCacheDataTable`, `GetIpNetTable`,`WNetOpenEnumW(RESOURCE_GLOBALNET, RESOURCETYPE_ANY)`,`NetServerEnum`,`GetTcpTable`, and `GetAdaptersAddresses.` |
| T1021.002 SMB/Windows Admin Shares |
MalwareHermeticWizard | HermeticWizard can use a list of hardcoded credentials to to authenticate via NTLMSSP to the SMB shares on remote systems. |
| T1027.013 Encrypted/Encoded File |
MalwareHermeticWizard | HermeticWizard has the ability to encrypt PE files with a reverse XOR loop. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHermeticWiper | HermeticWiper has used the name `postgressql.exe` to mask a malicious payload. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareHermeticWizard | HermeticWizard has been named `exec_32.dll` to mimic a legitimate MS Outlook .dll. |
| T1046 Network Service Discovery |
MalwareHermeticWizard | HermeticWizard has the ability to scan ports on a compromised network. |
| T1047 Windows Management Instrumentation |
MalwareHermeticWizard | HermeticWizard can use WMI to create a new process on a remote machine via `C:\windows\system32\cmd.exe /c start C:\windows\system32\\regsvr32.exe /s /iC:\windows\<filename>.dll`. |
| T1059.003 Windows Command Shell |
MalwareHermeticWizard | HermeticWizard can use `cmd.exe` for execution on compromised hosts. |
| T1059.003 Windows Command Shell |
MalwareHermeticWiper | HermeticWiper can use `cmd.exe /Q/c move CSIDL_SYSTEM_DRIVE\temp\sys.tmp1 CSIDL_WINDOWS\policydefinitions\postgresql.exe 1> \\127.0.0.1\ADMIN$\_1636727589.6007507 2>&1` to deploy on an infected system. |
| T1070 Indicator Removal |
MalwareHermeticWiper | HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services. |
| T1070.004 File Deletion |
MalwareHermeticWiper | HermeticWiper has the ability to overwrite its own file with random bites. |
| T1082 System Information Discovery |
MalwareHermeticWiper | HermeticWiper can determine the OS version and bitness on a targeted host. |
| T1106 Native API |
MalwareHermeticWizard | HermeticWizard can connect to remote shares using `WNetAddConnection2W`. |
| T1106 Native API |
MalwareHermeticWiper | HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data. |
| T1110.001 Password Guessing |
MalwareHermeticWizard | HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares. |
| T1218.010 Regsvr32 |
MalwareHermeticWizard | HermeticWizard has used `regsvr32.exe /s /i` to execute malicious payloads. |
| T1218.011 Rundll32 |
MalwareHermeticWizard | HermeticWizard has the ability to create a new process using `rundll32`. |
| T1484.001 Group Policy Modification |
MalwareHermeticWiper | HermeticWiper has the ability to deploy through an infected system's default domain policy. |
| T1485 Data Destruction |
MalwareHermeticWiper | HermeticWiper can recursively wipe folders and files in `Windows`, `Program Files`, `Program Files(x86)`, `PerfLogs`, `Boot, System`, `Volume Information`, and `AppData` folders using `FSCTL_MOVE_FILE`. HermeticWiper can also overwrite symbolic links and big files in `My Documents` and on the Desktop with random bytes. |
| T1490 Inhibit System Recovery |
MalwareHermeticWiper | HermeticWiper can disable the VSS service on a compromised host using the service control manager. |
| T1553.002 Code Signing |
MalwareHermeticWizard | HermeticWizard has been signed by valid certificates assigned to Hermetica Digital. |
| T1559.001 Component Object Model |
MalwareHermeticWizard | HermeticWizard can execute files on remote machines using DCOM. |
| T1569.002 Service Execution |
MalwareHermeticWizard | HermeticWizard can use `OpenRemoteServiceManager` to create a service. |
| T1570 Lateral Tool Transfer |
MalwareHermeticWizard | HermeticWizard can copy files to other machines on a compromised network. |
| T1680 Local Storage Discovery |
MalwareHermeticWiper | HermeticWiper can enumerate physical drives on a targeted host. |
| T1685.005 Clear Windows Event Logs |
MalwareHermeticWiper | HermeticWiper can overwrite the `C:\Windows\System32\winevt\Logs` file on a targeted system. |
| T1685.005 Clear Windows Event Logs |
MalwareHermeticWizard | HermeticWizard has the ability to use `wevtutil cl system` to clear event logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.