ATT&CKReferencesSentinelOne Valak June 2020

SentinelOne Valak June 2020

Reaves, J. and Platt, J. (2020, June). Valak Malware and the Connection to Gozi Loader ConfCrew. Retrieved August 31, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareValak

Valak has the ability to base64 encode and XOR encrypt strings.

T1027.002
Software Packing
MalwareValak

Valak has used packed DLL payloads.

T1027.011
Fileless Storage
MalwareValak

Valak has the ability to store information regarding the C2 server and downloads in the Registry key HKCU\Software\ApplicationContainer\Appsw64.

T1041
Exfiltration Over C2 Channel
MalwareValak

Valak has the ability to exfiltrate data over the C2 channel.

T1047
Windows Management Instrumentation
MalwareValak

Valak can use wmic process call create in a scheduled task to launch plugins and for execution.

T1053.005
Scheduled Task
MalwareValak

Valak has used scheduled tasks to execute additional payloads and to gain persistence on a compromised host.

T1082
System Information Discovery
MalwareValak

Valak can determine the Windows version and computer name on a compromised host.

T1112
Modify Registry
MalwareValak

Valak has the ability to modify the Registry key HKCU\Software\ApplicationContainer\Appsw64 to store information regarding the C2 server and downloads.

T1119
Automated Collection
MalwareValak

Valak can download a module to search for and build a report of harvested credential data.

T1204.002
Malicious File
MalwareValak

Valak has been executed via Microsoft Word documents containing malicious macros.

T1552.002
Credentials in Registry
MalwareValak

Valak can use the clientgrabber module to steal e-mail credentials from the Registry.

T1555.004
Windows Credential Manager
MalwareValak

Valak can use a .NET compiled module named exchgrabber to enumerate credentials from the Credential Manager.

T1559.002
Dynamic Data Exchange
MalwareValak

Valak can execute tasks via OLE.

T1564.004
NTFS File Attributes
MalwareValak

Valak has the ability save and execute files as alternate data streams (ADS).

T1566.002
Spearphishing Link
MalwareValak

Valak has been delivered via malicious links in e-mail.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.