Bourhis, P., Sekoia TDR. (2024, February 1). Unveiling the intricacies of DiceLoader. Retrieved May 14, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareLizar | Lizar has retrieved network information from a compromised host, such as the MAC address. |
| T1027 Obfuscated Files or Information |
MalwareLizar | Lizar has obfuscated the fingerprint of the victim system, the local IP address, and the Fowler-Noll-V 1 (FNV-1) hash of the local IP address using an XOR operation. The data is then sent to the C2 server. |
| T1033 System Owner/User Discovery |
MalwareLizar | Lizar can collect the username from the system. |
| T1082 System Information Discovery |
MalwareLizar | Lizar can collect the computer name from the machine. |
| T1095 Non-Application Layer Protocol |
MalwareLizar | Lizar has used a raw TCP connection to communicate with the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareLizar | Lizar can download additional plugins, files, and tools. |
| T1132.002 Non-Standard Encoding |
MalwareLizar | Lizar has used a complex XOR operation to obfuscate C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLizar | Lizar has decrypted its configuration data, such as the C2 IP address, ports and other network communication. |
| T1620 Reflective Code Loading |
MalwareLizar | Lizar has used the Reflective DLL injection module from Github to inject itself into a process’s memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.