ATT&CKReferencesPWC WellMess C2 August 2020

PWC WellMess C2 August 2020

PWC. (2020, August 17). WellMess malware: analysis of its Command and Control (C2) server. Retrieved September 29, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareWellMess

WellMess can use HTTP and HTTPS in C2 communications.

T1140
Deobfuscate/Decode Files or Information
MalwareWellMess

WellMess can decode and decrypt data received from C2.

T1573.001
Symmetric Cryptography
MalwareWellMess

WellMess can encrypt HTTP POST data using RC6 and a dynamically generated AES key encrypted with a hard coded RSA public key.

T1573.002
Asymmetric Cryptography
MalwareWellMess

WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates.

T1587.003
Digital Certificates
GroupAPT29

APT29 has created self-signed digital certificates to enable mutual TLS authentication for malware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.