T1057 Process Discovery |
MalwareTONESHELL |
TONESHELL has checked the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler. TONESHELL has also searched for running antivirus processes to include ESET’s antivirus associated executables ekrn.exe and egui.exe. |
T1072 Software Deployment Tools |
GroupMustang Panda |
Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls. |
T1082 System Information Discovery |
MalwareTONESHELL |
TONESHELL has the ability to retrieve the name of the infected machine. |
T1106 Native API |
GroupMustang Panda |
Mustang Panda has used various Windows API calls during execution and defense evasion. |
T1106 Native API |
MalwareTONESHELL |
TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function. |
T1140 Deobfuscate/Decode Files or Information |
MalwareTONESHELL |
TONESHELL has decoded its payload prior to execution. |
T1204.002 Malicious File |
GroupMustang Panda |
Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. |
T1205 Traffic Signaling |
MalwareTONESHELL |
TONESHELL has utilized a magic value in C2 communications and only executes in memory when response packets match specific values. |
T1218.010 Regsvr32 |
MalwareTONESHELL |
TONESHELL has used regsvr32.exe to execute the windows `DLLRegisterServer` function. |
T1218.013 Mavinject |
MalwareTONESHELL |
TONESHELL has injected its malicious payload into a running process through Windows utility Microsoft Application Virtualization Injector `MAVInject.exe`. |
T1480 Execution Guardrails |
MalwareTONESHELL |
TONESHELL has an exception handler that executes when ESET antivirus applications `ekrn.exe` and `egui.exe` are not found and directly injects its code into waitfor.exe using Native Windows API including `WriteProcessMemory` and `CreateRemoteThreadEx`. |
T1480.001 Environmental Keying |
MalwareTONESHELL |
TONESHELL has generated unique GUIDs to identify victim devices. TONESHELL has leveraged environmental keying in payload delivery using the victim computer name and other configuration values. TONESHELL has also tracked IDs associated with reverse shell subprocesses to manage interactions and terminations from C2. |
T1518.001 Security Software Discovery |
MalwareTONESHELL |
TONESHELL has checked for the presence of ESET antivirus applications `ekrn.exe` and `egui.exe`. |
T1574.001 DLL |
GroupMustang Panda |
Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. |
T1574.001 DLL |
MalwareTONESHELL |
TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe. |
T1574.005 Executable Installer File Permissions Weakness |
GroupMustang Panda |
Mustang Panda has leveraged legitimate software installer executables such as Setup Factory “IRSetup.exe” to drop and execute their payload. |
T1583.001 Domains |
GroupMustang Panda |
Mustang Panda has acquired C2 domains prior to operations. |