ATT&CKReferencesESET Ebury Oct 2017

ESET Ebury Oct 2017

Vachon, F. (2017, October 30). Windigo Still not Windigone: An Ebury Update . Retrieved February 10, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareEbury

Ebury has implemented a fallback mechanism to begin using a DGA when the attacker hasn't connected to the infected system for three days.

T1014
Rootkit
MalwareEbury

Ebury acts as a user land rootkit using the SSH service.

T1059.006
Python
MalwareEbury

Ebury has used Python to implement its DGA.

T1140
Deobfuscate/Decode Files or Information
MalwareEbury

Ebury has verified C2 domain ownership by decrypting the TXT record using an embedded RSA public key.

T1556.003
Pluggable Authentication Modules
MalwareEbury

Ebury can deactivate PAM modules to tamper with the sshd configuration.

T1568.002
Domain Generation Algorithms
MalwareEbury

Ebury has used a DGA to generate a domain name for C2.

T1574.006
Dynamic Linker Hijacking
MalwareEbury

When Ebury is running as an OpenSSH server, it uses LD_PRELOAD to inject its malicious shared module in to programs launched by SSH sessions. Ebury hooks the following functions from `libc` to inject into subprocesses; `system`, `popen`, `execve`, `execvpe`, `execv`, `execvp`, and `execl`.

T1685
Disable or Modify Tools
MalwareEbury

Ebury can disable SELinux Role-Based Access Control and deactivate PAM modules.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.