Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
Azorult can check for installed software on the system under the Registry key |
| T1016 System Network Configuration Discovery |
Azorult can collect host IP information from the victim’s machine. |
| T1033 System Owner/User Discovery |
Azorult can collect the username from the victim’s machine. |
| T1055.012 Process Hollowing |
Azorult can decrypt the payload into memory, create a new suspended process of itself, then inject a decrypted payload to the new process and resume new process execution. |
| T1057 Process Discovery |
Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot. |
| T1070.004 File Deletion |
Azorult can delete files from victim machines. |
| T1082 System Information Discovery |
Azorult can collect the machine information, system architecture, the OS version, computer name, Windows product name, the number of CPU cores, video card information, and the system language. |
| T1083 File and Directory Discovery |
Azorult can recursively search for files in folders and collects files from the desktop with certain extensions. |
| T1105 Ingress Tool Transfer |
Azorult can download and execute additional files. Azorult has also downloaded a ransomware payload called Hermes. |
| T1113 Screen Capture |
Azorult can capture screenshots of the victim’s machines. |
| T1124 System Time Discovery |
Azorult can collect the time zone information from the system. |
| T1134.002 Create Process with Token |
Azorult can call WTSQueryUserToken and CreateProcessAsUser to start a new process with local system privileges. |
| T1140 Deobfuscate/Decode Files or Information |
Azorult uses an XOR key to decrypt content and uses Base64 to decode the C2 address. |
| T1552.001 Credentials In Files |
Azorult can steal credentials in files belonging to common software such as Skype, Telegram, and Steam. |
| T1555.003 Credentials from Web Browsers |
Azorult can steal credentials from the victim's browser. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.