ATT&CKReferencesESET Ebury Feb 2014

ESET Ebury Feb 2014

M.Léveillé, M.. (2014, February 21). An In-depth Analysis of Linux/Ebury. Retrieved April 19, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareEbury

Ebury has obfuscated its strings with a simple XOR encryption with a static key.

T1071.004
DNS
MalwareEbury

Ebury has used DNS requests over UDP port 53 for C2.

T1132.001
Standard Encoding
MalwareEbury

Ebury has encoded C2 traffic in hexadecimal format.

T1552.004
Private Keys
MalwareEbury

Ebury has intercepted unencrypted private keys as well as private key pass-phrases.

T1553.002
Code Signing
MalwareEbury

Ebury has installed a self-signed RPM package mimicking the original system package on RPM based systems.

T1554
Compromise Host Software Binary
MalwareEbury

Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library.

T1556
Modify Authentication Process
MalwareEbury

Ebury can intercept private keys using a trojanized ssh-add function.

T1568.002
Domain Generation Algorithms
MalwareEbury

Ebury has used a DGA to generate a domain name for C2.

T1573.001
Symmetric Cryptography
MalwareEbury

Ebury has encrypted C2 traffic using the client IP address, then encoded it as a hexadecimal string.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.