Hi-Zor

S0087

Malware.View on attack.mitre.org

About this malware

Hi-Zor is a remote access tool (RAT) that has characteristics similar to Sakula. It was used in a campaign named INOCNATION.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Hi-Zor uses various XOR techniques to obfuscate its components.

T1059.003
Windows Command Shell

Hi-Zor has the ability to create a reverse shell.

T1070.004
File Deletion

Hi-Zor deletes its RAT installer file as it executes its DLL payload file.

T1071.001
Web Protocols

Hi-Zor communicates with its C2 server over HTTPS.

T1105
Ingress Tool Transfer

Hi-Zor has the ability to upload and download files from its C2 server.

T1218.010
Regsvr32

Hi-Zor executes using regsvr32.exe called from the Registry Run Keys / Startup Folder persistence mechanism.

T1547.001
Registry Run Keys / Startup Folder

Hi-Zor creates a Registry Run key to establish persistence.

T1573.001
Symmetric Cryptography

Hi-Zor encrypts C2 traffic with a double XOR using two distinct single-byte keys.

T1573.002
Asymmetric Cryptography

Hi-Zor encrypts C2 traffic with TLS.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Fidelis Hi-Zor Open source
    Fidelis Threat Research Team. (2016, January 27). Introducing Hi-Zor RAT. Retrieved March 24, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.