PWC. (2020, August 17). WellMess malware: analysis of its Command and Control (C2) server. Retrieved September 29, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1071.001 Web Protocols |
MalwareWellMess | WellMess can use HTTP and HTTPS in C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWellMess | WellMess can decode and decrypt data received from C2. |
| T1573.001 Symmetric Cryptography |
MalwareWellMess | WellMess can encrypt HTTP POST data using RC6 and a dynamically generated AES key encrypted with a hard coded RSA public key. |
| T1573.002 Asymmetric Cryptography |
MalwareWellMess | WellMess can communicate to C2 with mutual TLS where client and server mutually check certificates. |
| T1587.003 Digital Certificates |
GroupAPT29 | APT29 has created self-signed digital certificates to enable mutual TLS authentication for malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.