Malware.View on attack.mitre.org
Prikormka is a malware family used in a campaign known as Operation Groundbait. It has predominantly been observed in Ukraine and was used as early as 2008.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
A module in Prikormka collects information from the victim about its IP addresses and MAC addresses. |
| T1025 Data from Removable Media |
Prikormka contains a module that collects documents with certain extensions from removable media or fixed drives connected via USB. |
| T1027.013 Encrypted/Encoded File |
Some resources in Prikormka are encrypted with a simple XOR operation or encoded with Base64. |
| T1033 System Owner/User Discovery |
A module in Prikormka collects information from the victim about the current user name. |
| T1056.001 Keylogging |
Prikormka contains a keylogger module that collects keystrokes and the titles of foreground windows. |
| T1070.004 File Deletion |
After encrypting its own log files, the log encryption module in Prikormka deletes the original, unencrypted files from the host. |
| T1074.001 Local Data Staging |
Prikormka creates a directory, |
| T1082 System Information Discovery |
A module in Prikormka collects information from the victim about Windows OS version, computer name, battery info, and physical memory. |
| T1083 File and Directory Discovery |
A module in Prikormka collects information about the paths, size, and creation time of files with specific file extensions, but not the actual content of the file. |
| T1113 Screen Capture |
Prikormka contains a module that captures screenshots of the victim's desktop. |
| T1120 Peripheral Device Discovery |
A module in Prikormka collects information on available printers and disk drives. |
| T1132.001 Standard Encoding |
Prikormka encodes C2 traffic with Base64. |
| T1218.011 Rundll32 |
Prikormka uses rundll32.exe to load its DLL. |
| T1518.001 Security Software Discovery |
A module in Prikormka collects information from the victim about installed anti-virus software. |
| T1547.001 Registry Run Keys / Startup Folder |
Prikormka adds itself to a Registry Run key with the name guidVGA or guidVSA. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.