ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareZebrocy | Zebrocy gets the username from the system. |
| T1037.001 Logon Script (Windows) |
MalwareZebrocy | Zebrocy performs persistence with a logon script via adding to the Registry key |
| T1057 Process Discovery |
MalwareZebrocy | Zebrocy uses the |
| T1070.004 File Deletion |
MalwareZebrocy | Zebrocy has a command to delete files and directories. |
| T1071.001 Web Protocols |
MalwareZebrocy | Zebrocy uses HTTP for C2. |
| T1071.003 Mail Protocols |
MalwareZebrocy | Zebrocy uses SMTP and POP3 for C2. |
| T1074.001 Local Data Staging |
MalwareZebrocy | Zebrocy stores all collected information in a single file before exfiltration. |
| T1082 System Information Discovery |
MalwareZebrocy | Zebrocy collects the OS version and computer name. Zebrocy also runs the |
| T1083 File and Directory Discovery |
MalwareZebrocy | Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the |
| T1113 Screen Capture |
MalwareZebrocy | A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format. |
| T1119 Automated Collection |
MalwareZebrocy | Zebrocy scans the system and automatically collects files with the following extensions: .doc, .docx, ,.xls, .xlsx, .pdf, .pptx, .rar, .zip, .jpg, .jpeg, .bmp, .tiff, .kum, .tlg, .sbx, .cr, .hse, .hsf, and .lhz. |
| T1124 System Time Discovery |
MalwareZebrocy | Zebrocy gathers the current time zone and date information from the system. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareZebrocy | Zebrocy decodes its secondary payload and writes it to the victim’s machine. Zebrocy also uses AES and XOR to decrypt strings and payloads. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareZebrocy | Zebrocy creates an entry in a Registry Run key for the malware to execute on startup. |
| T1560 Archive Collected Data |
MalwareZebrocy | Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration. |
| T1573.002 Asymmetric Cryptography |
MalwareZebrocy | Zebrocy uses SSL and AES ECB for encrypting C2 communications. |
| T1680 Local Storage Discovery |
MalwareZebrocy | Zebrocy collects the serial number for the storage volume C:\. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.