ATT&CKReferencesESET Zebrocy Nov 2018

ESET Zebrocy Nov 2018

ESET. (2018, November 20). Sednit: What’s going on with Zebrocy?. Retrieved February 12, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareZebrocy

Zebrocy gets the username from the system.

T1037.001
Logon Script (Windows)
MalwareZebrocy

Zebrocy performs persistence with a logon script via adding to the Registry key HKCU\Environment\UserInitMprLogonScript.

T1057
Process Discovery
MalwareZebrocy

Zebrocy uses the tasklist and wmic process get Capture, ExecutablePath commands to gather the processes running on the system.

T1070.004
File Deletion
MalwareZebrocy

Zebrocy has a command to delete files and directories.

T1071.001
Web Protocols
MalwareZebrocy

Zebrocy uses HTTP for C2.

T1071.003
Mail Protocols
MalwareZebrocy

Zebrocy uses SMTP and POP3 for C2.

T1074.001
Local Data Staging
MalwareZebrocy

Zebrocy stores all collected information in a single file before exfiltration.

T1082
System Information Discovery
MalwareZebrocy

Zebrocy collects the OS version and computer name. Zebrocy also runs the systeminfo command to gather system information.

T1083
File and Directory Discovery
MalwareZebrocy

Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the echo %APPDATA% command to list the contents of the directory. Zebrocy can obtain the current execution path as well as perform drive enumeration.

T1113
Screen Capture
MalwareZebrocy

A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format.

T1119
Automated Collection
MalwareZebrocy

Zebrocy scans the system and automatically collects files with the following extensions: .doc, .docx, ,.xls, .xlsx, .pdf, .pptx, .rar, .zip, .jpg, .jpeg, .bmp, .tiff, .kum, .tlg, .sbx, .cr, .hse, .hsf, and .lhz.

T1124
System Time Discovery
MalwareZebrocy

Zebrocy gathers the current time zone and date information from the system.

T1140
Deobfuscate/Decode Files or Information
MalwareZebrocy

Zebrocy decodes its secondary payload and writes it to the victim’s machine. Zebrocy also uses AES and XOR to decrypt strings and payloads.

T1547.001
Registry Run Keys / Startup Folder
MalwareZebrocy

Zebrocy creates an entry in a Registry Run key for the malware to execute on startup.

T1560
Archive Collected Data
MalwareZebrocy

Zebrocy has used a method similar to RC4 as well as AES for encryption and hexadecimal for encoding data before exfiltration.

T1573.002
Asymmetric Cryptography
MalwareZebrocy

Zebrocy uses SSL and AES ECB for encrypting C2 communications.

T1680
Local Storage Discovery
MalwareZebrocy

Zebrocy collects the serial number for the storage volume C:\.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.