H1N1

S0132

Malware.View on attack.mitre.org

About this malware

H1N1 is a malware variant that has been distributed via a campaign using VBA macros to infect victims. Although it initially had only loader capabilities, it has evolved to include information-stealing functionality.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1027
Obfuscated Files or Information

H1N1 uses multiple techniques to obfuscate strings, including XOR.

T1027.002
Software Packing

H1N1 uses a custom packing algorithm.

T1059.003
Windows Command Shell

H1N1 kills and disables services by using cmd.exe.

T1080
Taint Shared Content

H1N1 has functionality to copy itself to network shares.

T1091
Replication Through Removable Media

H1N1 has functionality to copy itself to removable media.

T1105
Ingress Tool Transfer

H1N1 contains a command to download and execute a file from a remotely hosted URL using WinINet HTTP requests.

T1132
Data Encoding

H1N1 obfuscates C2 traffic with an altered version of base64.

T1490
Inhibit System Recovery

H1N1 disable recovery options and deletes shadow copies from the victim.

T1548.002
Bypass User Account Control

H1N1 bypasses user access control by using a DLL hijacking vulnerability in the Windows Update Standalone Installer (wusa.exe).

T1555.003
Credentials from Web Browsers

H1N1 dumps usernames and passwords from Firefox, Internet Explorer, and Outlook.

T1573.001
Symmetric Cryptography

H1N1 encrypts C2 traffic using an RC4 key.

T1685
Disable or Modify Tools

H1N1 kills and disables services for Windows Security Center, and Windows Defender.

T1686.003
Windows Host Firewall

H1N1 kills and disables services for Windows Firewall.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Cisco H1N1 Part 1 Open source
    Reynolds, J.. (2016, September 13). H1N1: Technical analysis reveals new capabilities. Retrieved September 26, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.