ATT&CKReferencesFireEye NETWIRE March 2019

FireEye NETWIRE March 2019

Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareNETWIRE

NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names.

T1049
System Network Connections Discovery
MalwareNETWIRE

NETWIRE can capture session logon details from a compromised host.

T1053.005
Scheduled Task
MalwareNETWIRE

NETWIRE can create a scheduled task to establish persistence.

T1055.012
Process Hollowing
MalwareNETWIRE

The NETWIRE payload has been injected into benign Microsoft executables via process hollowing.

T1056.001
Keylogging
MalwareNETWIRE

NETWIRE can perform keylogging.

T1057
Process Discovery
MalwareNETWIRE

NETWIRE can discover processes on compromised hosts.

T1059.001
PowerShell
MalwareNETWIRE

The NETWIRE binary has been executed via PowerShell script.

T1059.005
Visual Basic
MalwareNETWIRE

NETWIRE has been executed through use of VBScripts.

T1074.001
Local Data Staging
MalwareNETWIRE

NETWIRE has the ability to write collected data to a file created in the ./LOGS directory.

T1102
Web Service
MalwareNETWIRE

NETWIRE has used web services including Paste.ee to host payloads.

T1105
Ingress Tool Transfer
MalwareNETWIRE

NETWIRE can downloaded payloads from C2 to the compromised host.

T1106
Native API
MalwareNETWIRE

NETWIRE can use Native API including CreateProcess GetProcessById, and WriteProcessMemory.

T1113
Screen Capture
MalwareNETWIRE

NETWIRE can capture the victim's screen.

T1204.001
Malicious Link
MalwareNETWIRE

NETWIRE has been executed through convincing victims into clicking malicious links.

T1204.001
Malicious Link
GroupTA2541

TA2541 has used malicious links to cloud and web services to gain execution on victim machines.

T1204.002
Malicious File
MalwareNETWIRE

NETWIRE has been executed through luring victims into opening malicious documents.

T1555.003
Credentials from Web Browsers
MalwareNETWIRE

NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome.

T1560.003
Archive via Custom Method
MalwareNETWIRE

NETWIRE has used a custom encryption algorithm to encrypt collected data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.