Falcone, R. and Miller-Osborn, J. (2016, February 3). Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?. Retrieved February 15, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareEmissary | Emissary has the capability to execute the command |
| T1016 System Network Configuration Discovery |
MalwareEmissary | Emissary has the capability to execute the command |
| T1027.001 Binary Padding |
MalwareEmissary | A variant of Emissary appends junk data to the end of its DLL file to create a large file that may exceed the maximum size that anti-virus programs can scan. |
| T1027.013 Encrypted/Encoded File |
MalwareEmissary | Variants of Emissary encrypt payloads using various XOR ciphers, as well as a custom algorithm that uses the "srand" and "rand" functions. |
| T1069.001 Local Groups |
MalwareEmissary | Emissary has the capability to execute the command |
| T1082 System Information Discovery |
MalwareEmissary | Emissary has the capability to execute ver and systeminfo commands. |
| T1218.011 Rundll32 |
MalwareEmissary | Variants of Emissary have used rundll32.exe in Registry values added to establish persistence. |
| T1543.003 Windows Service |
MalwareEmissary | Emissary is capable of configuring itself as a service. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEmissary | Variants of Emissary have added Run Registry keys to establish persistence. |
| T1615 Group Policy Discovery |
MalwareEmissary | Emissary has the capability to execute |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.