ATT&CKReferencesUS-CERT Volgmer 2 Nov 2017

US-CERT Volgmer 2 Nov 2017

US-CERT. (2017, November 01). Malware Analysis Report (MAR) - 10135536-D. Retrieved July 16, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareVolgmer

Volgmer checks the system for certain Registry keys.

T1027.013
Encrypted/Encoded File
MalwareVolgmer

A Volgmer variant is encoded using a simple XOR cipher.

T1036.004
Masquerade Task or Service
MalwareVolgmer

Some Volgmer variants add new services with display names generated by a list of hard-coded strings such as Application, Background, Security, and Windows, presumably as a way to masquerade as a legitimate service.

T1059.003
Windows Command Shell
MalwareVolgmer

Volgmer can execute commands on the victim's machine.

T1070.004
File Deletion
MalwareVolgmer

Volgmer can delete files and itself after infection to avoid analysis.

T1082
System Information Discovery
MalwareVolgmer

Volgmer can gather system information, the computer name, OS version, drive and serial information from the victim's machine.

T1105
Ingress Tool Transfer
MalwareVolgmer

Volgmer can download remote files and additional payloads to the victim's machine.

T1106
Native API
MalwareVolgmer

Volgmer executes payloads using the Windows API call CreateProcessW().

T1112
Modify Registry
MalwareVolgmer

Volgmer modifies the Registry to store an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1140
Deobfuscate/Decode Files or Information
MalwareVolgmer

Volgmer deobfuscates its strings and APIs once its executed.

T1543.003
Windows Service
MalwareVolgmer

Volgmer installs a copy of itself in a randomly selected service, then overwrites the ServiceDLL entry in the service's Registry entry. Some Volgmer variants also install .dll files as services with names generated by a list of hard-coded strings.

T1573.001
Symmetric Cryptography
MalwareVolgmer

Volgmer uses a simple XOR cipher to encrypt traffic and files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.