ATT&CKSoftwareHTTPBrowser

HTTPBrowser

S0070

Malware.View on attack.mitre.org

About this malware

HTTPBrowser is malware that has been used by several threat groups. It is believed to be of Chinese origin.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027
Obfuscated Files or Information

HTTPBrowser's code may be obfuscated through structured exception handling and return-oriented programming.

T1036.005
Match Legitimate Resource Name or Location

HTTPBrowser's installer contains a malicious file named navlu.dll to decrypt and run the RAT. navlu.dll is also the name of a legitimate Symantec DLL.

T1056.001
Keylogging

HTTPBrowser is capable of capturing keystrokes on victims.

T1059.003
Windows Command Shell

HTTPBrowser is capable of spawning a reverse shell on a victim.

T1070.004
File Deletion

HTTPBrowser deletes its original installer file once installation is complete.

T1071.001
Web Protocols

HTTPBrowser has used HTTP and HTTPS for command and control.

T1071.004
DNS

HTTPBrowser has used DNS for command and control.

T1083
File and Directory Discovery

HTTPBrowser is capable of listing files, folders, and drives on a victim.

T1105
Ingress Tool Transfer

HTTPBrowser is capable of writing a file to the compromised system from the C2 server.

T1547.001
Registry Run Keys / Startup Folder

HTTPBrowser has established persistence by setting the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key value for wdm to the path of the executable. It has also used the Registry entry HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run vpdn “%ALLUSERPROFILE%\%APPDATA%\vpdn\VPDN_LU.exe” to establish persistence.

T1574.001
DLL

HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll. HTTPBrowser has also used DLL side-loading.

Groups that use it2

Campaigns0

None recorded.

References3

  1. Dell TG-3390 Open source
    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.
  2. ThreatConnect Anthem Open source
    ThreatConnect Research Team. (2015, February 27). The Anthem Hack: All Roads Lead to China. Retrieved January 26, 2016.
  3. ThreatStream Evasion Analysis Open source
    Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.