ATT&CKReferencesCisco H1N1 Part 2

Cisco H1N1 Part 2

Reynolds, J.. (2016, September 14). H1N1: Technical analysis reveals new capabilities – part 2. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareH1N1

H1N1 kills and disables services by using cmd.exe.

T1080
Taint Shared Content
MalwareH1N1

H1N1 has functionality to copy itself to network shares.

T1091
Replication Through Removable Media
MalwareH1N1

H1N1 has functionality to copy itself to removable media.

T1105
Ingress Tool Transfer
MalwareH1N1

H1N1 contains a command to download and execute a file from a remotely hosted URL using WinINet HTTP requests.

T1132
Data Encoding
MalwareH1N1

H1N1 obfuscates C2 traffic with an altered version of base64.

T1490
Inhibit System Recovery
MalwareH1N1

H1N1 disable recovery options and deletes shadow copies from the victim.

T1548.002
Bypass User Account Control
MalwareH1N1

H1N1 bypasses user access control by using a DLL hijacking vulnerability in the Windows Update Standalone Installer (wusa.exe).

T1555.003
Credentials from Web Browsers
MalwareH1N1

H1N1 dumps usernames and passwords from Firefox, Internet Explorer, and Outlook.

T1573.001
Symmetric Cryptography
MalwareH1N1

H1N1 encrypts C2 traffic using an RC4 key.

T1685
Disable or Modify Tools
MalwareH1N1

H1N1 kills and disables services for Windows Security Center, and Windows Defender.

T1686.003
Windows Host Firewall
MalwareH1N1

H1N1 kills and disables services for Windows Firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.