Pisloader

S0124

Malware.View on attack.mitre.org

About this malware

Pisloader is a malware family that is notable due to its use of DNS as a C2 protocol as well as its use of anti-analysis tactics. It has been used by APT18 and is similar to another malware family, HTTPBrowser, that has been used by the group.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1016
System Network Configuration Discovery

Pisloader has a command to collect the victim's IP address.

T1027
Obfuscated Files or Information

Pisloader obfuscates files by splitting strings into smaller sub-strings and including "garbage" strings that are never used. The malware also uses return-oriented programming (ROP) technique and single-byte XOR to obfuscate data.

T1059.003
Windows Command Shell

Pisloader uses cmd.exe to set the Registry Run key value. It also has a command to spawn a command shell.

T1071.004
DNS

Pisloader uses DNS as its C2 protocol.

T1082
System Information Discovery

Pisloader has a command to collect victim system information, including the system name and OS version.

T1083
File and Directory Discovery

Pisloader has commands to list drives on the victim machine and to list file information for a given directory.

T1105
Ingress Tool Transfer

Pisloader has a command to upload a file to the victim machine.

T1132.001
Standard Encoding

Responses from the Pisloader C2 server are base32-encoded.

T1547.001
Registry Run Keys / Startup Folder

Pisloader establishes persistence via a Registry Run key.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Palo Alto DNS Requests Open source
    Grunzweig, J., et al. (2016, May 24). New Wekby Attacks Use DNS Requests As Command and Control Mechanism. Retrieved August 17, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.