ATT&CKReferencesFidelis INOCNATION

Fidelis INOCNATION

Fidelis Cybersecurity. (2015, December 16). Fidelis Threat Advisory #1020: Dissecting the Malware Involved in the INOCNATION Campaign. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareHi-Zor

Hi-Zor uses various XOR techniques to obfuscate its components.

T1059.003
Windows Command Shell
MalwareHi-Zor

Hi-Zor has the ability to create a reverse shell.

T1070.004
File Deletion
MalwareHi-Zor

Hi-Zor deletes its RAT installer file as it executes its DLL payload file.

T1071.001
Web Protocols
MalwareHi-Zor

Hi-Zor communicates with its C2 server over HTTPS.

T1105
Ingress Tool Transfer
MalwareHi-Zor

Hi-Zor has the ability to upload and download files from its C2 server.

T1218.010
Regsvr32
MalwareHi-Zor

Hi-Zor executes using regsvr32.exe called from the Registry Run Keys / Startup Folder persistence mechanism.

T1547.001
Registry Run Keys / Startup Folder
MalwareHi-Zor

Hi-Zor creates a Registry Run key to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.