M.Léveillé, M.. (2014, February 21). An In-depth Analysis of Linux/Ebury. Retrieved April 19, 2019.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareEbury | Ebury has obfuscated its strings with a simple XOR encryption with a static key. |
| T1071.004 DNS |
MalwareEbury | Ebury has used DNS requests over UDP port 53 for C2. |
| T1132.001 Standard Encoding |
MalwareEbury | Ebury has encoded C2 traffic in hexadecimal format. |
| T1552.004 Private Keys |
MalwareEbury | Ebury has intercepted unencrypted private keys as well as private key pass-phrases. |
| T1553.002 Code Signing |
MalwareEbury | Ebury has installed a self-signed RPM package mimicking the original system package on RPM based systems. |
| T1554 Compromise Host Software Binary |
MalwareEbury | Ebury modifies the `keyutils` library to add malicious behavior to the OpenSSH client and the curl library. |
| T1556 Modify Authentication Process |
MalwareEbury | Ebury can intercept private keys using a trojanized |
| T1568.002 Domain Generation Algorithms |
MalwareEbury | Ebury has used a DGA to generate a domain name for C2. |
| T1573.001 Symmetric Cryptography |
MalwareEbury | Ebury has encrypted C2 traffic using the client IP address, then encoded it as a hexadecimal string. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.