Reaves, J. and Platt, J. (2020, June). Valak Malware and the Connection to Gozi Loader ConfCrew. Retrieved August 31, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareValak | Valak has the ability to base64 encode and XOR encrypt strings. |
| T1027.002 Software Packing |
MalwareValak | Valak has used packed DLL payloads. |
| T1027.011 Fileless Storage |
MalwareValak | Valak has the ability to store information regarding the C2 server and downloads in the Registry key |
| T1041 Exfiltration Over C2 Channel |
MalwareValak | Valak has the ability to exfiltrate data over the C2 channel. |
| T1047 Windows Management Instrumentation |
MalwareValak | Valak can use |
| T1053.005 Scheduled Task |
MalwareValak | Valak has used scheduled tasks to execute additional payloads and to gain persistence on a compromised host. |
| T1082 System Information Discovery |
MalwareValak | Valak can determine the Windows version and computer name on a compromised host. |
| T1112 Modify Registry |
MalwareValak | Valak has the ability to modify the Registry key |
| T1119 Automated Collection |
MalwareValak | Valak can download a module to search for and build a report of harvested credential data. |
| T1204.002 Malicious File |
MalwareValak | Valak has been executed via Microsoft Word documents containing malicious macros. |
| T1552.002 Credentials in Registry |
MalwareValak | Valak can use the clientgrabber module to steal e-mail credentials from the Registry. |
| T1555.004 Windows Credential Manager |
MalwareValak | Valak can use a .NET compiled module named exchgrabber to enumerate credentials from the Credential Manager. |
| T1559.002 Dynamic Data Exchange |
MalwareValak | Valak can execute tasks via OLE. |
| T1564.004 NTFS File Attributes |
MalwareValak | Valak has the ability save and execute files as alternate data streams (ADS). |
| T1566.002 Spearphishing Link |
MalwareValak | Valak has been delivered via malicious links in e-mail. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.