ATT&CKReferencesFireEye Metamorfo Apr 2018

FireEye Metamorfo Apr 2018

Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareMetamorfo

Metamorfo can enumerate all windows on the victim’s machine.

T1056.002
GUI Input Capture
MalwareMetamorfo

Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims.

T1059.005
Visual Basic
MalwareMetamorfo

Metamorfo has used VBS code on victims’ systems.

T1070
Indicator Removal
MalwareMetamorfo

Metamorfo has a command to delete a Registry key it uses, \Software\Microsoft\Internet Explorer\notes.

T1082
System Information Discovery
MalwareMetamorfo

Metamorfo has collected the hostname and operating system version from the compromised host.

T1083
File and Directory Discovery
MalwareMetamorfo

Metamorfo has searched the Program Files directories for specific folders and has searched for strings related to its mutexes.

T1095
Non-Application Layer Protocol
MalwareMetamorfo

Metamorfo has used raw TCP for C2.

T1102.003
One-Way Communication
MalwareMetamorfo

Metamorfo has downloaded a zip file for execution on the system.

T1105
Ingress Tool Transfer
MalwareMetamorfo

Metamorfo has used MSI files to download additional files to execute.

T1112
Modify Registry
MalwareMetamorfo

Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key.

T1113
Screen Capture
MalwareMetamorfo

Metamorfo can collect screenshots of the victim’s machine.

T1119
Automated Collection
MalwareMetamorfo

Metamorfo has automatically collected mouse clicks, continuous screenshots on the machine, and set timers to collect the contents of the clipboard and website browsing.

T1140
Deobfuscate/Decode Files or Information
MalwareMetamorfo

Upon execution, Metamorfo has unzipped itself after being downloaded to the system and has performed string decryption.

T1204.002
Malicious File
MalwareMetamorfo

Metamorfo requires the user to double-click the executable to run the malicious HTA file or to download a malicious installer.

T1218.005
Mshta
MalwareMetamorfo

Metamorfo has used mshta.exe to execute a HTA payload.

T1518
Software Discovery
MalwareMetamorfo

Metamorfo has searched the compromised system for banking applications.

T1547.001
Registry Run Keys / Startup Folder
MalwareMetamorfo

Metamorfo has configured persistence to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run, Spotify =% APPDATA%\Spotify\Spotify.exe and used .LNK files in the startup folder to achieve persistence.

T1566.001
Spearphishing Attachment
MalwareMetamorfo

Metamorfo has been delivered to victims via emails with malicious HTML attachments.

T1571
Non-Standard Port
MalwareMetamorfo

Metamorfo has communicated with hosts over raw TCP on port 9999.

T1574.001
DLL
MalwareMetamorfo

Metamorfo has side-loaded its malicious DLL file.

T1685
Disable or Modify Tools
MalwareMetamorfo

Metamorfo has a function to kill processes associated with defenses and can prevent certain processes from launching.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.