Malware.View on attack.mitre.org
HTTPBrowser is malware that has been used by several threat groups. It is believed to be of Chinese origin.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
HTTPBrowser's code may be obfuscated through structured exception handling and return-oriented programming. |
| T1036.005 Match Legitimate Resource Name or Location |
HTTPBrowser's installer contains a malicious file named navlu.dll to decrypt and run the RAT. navlu.dll is also the name of a legitimate Symantec DLL. |
| T1056.001 Keylogging |
HTTPBrowser is capable of capturing keystrokes on victims. |
| T1059.003 Windows Command Shell |
HTTPBrowser is capable of spawning a reverse shell on a victim. |
| T1070.004 File Deletion |
HTTPBrowser deletes its original installer file once installation is complete. |
| T1071.001 Web Protocols |
HTTPBrowser has used HTTP and HTTPS for command and control. |
| T1071.004 DNS |
HTTPBrowser has used DNS for command and control. |
| T1083 File and Directory Discovery |
HTTPBrowser is capable of listing files, folders, and drives on a victim. |
| T1105 Ingress Tool Transfer |
HTTPBrowser is capable of writing a file to the compromised system from the C2 server. |
| T1547.001 Registry Run Keys / Startup Folder |
HTTPBrowser has established persistence by setting the |
| T1574.001 DLL |
HTTPBrowser abuses the Windows DLL load order by using a legitimate Symantec anti-virus binary, VPDN_LU.exe, to load a malicious DLL that mimics a legitimate Symantec DLL, navlu.dll. HTTPBrowser has also used DLL side-loading. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.