ATT&CKReferencesSymantec Volgmer Aug 2014

Symantec Volgmer Aug 2014

Yagi, J. (2014, August 24). Trojan.Volgmer. Retrieved July 16, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareVolgmer

Volgmer can gather the IP address from the victim's machine.

T1027.011
Fileless Storage
MalwareVolgmer

Volgmer stores an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1036.004
Masquerade Task or Service
MalwareVolgmer

Some Volgmer variants add new services with display names generated by a list of hard-coded strings such as Application, Background, Security, and Windows, presumably as a way to masquerade as a legitimate service.

T1049
System Network Connections Discovery
MalwareVolgmer

Volgmer can gather information about TCP connection state.

T1057
Process Discovery
MalwareVolgmer

Volgmer can gather a list of processes.

T1082
System Information Discovery
MalwareVolgmer

Volgmer can gather system information, the computer name, OS version, drive and serial information from the victim's machine.

T1105
Ingress Tool Transfer
MalwareVolgmer

Volgmer can download remote files and additional payloads to the victim's machine.

T1112
Modify Registry
MalwareVolgmer

Volgmer modifies the Registry to store an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.

T1543.003
Windows Service
MalwareVolgmer

Volgmer installs a copy of itself in a randomly selected service, then overwrites the ServiceDLL entry in the service's Registry entry. Some Volgmer variants also install .dll files as services with names generated by a list of hard-coded strings.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.