Denis

S0354

Malware.View on attack.mitre.org

About this malware

Denis is a Windows backdoor and Trojan used by APT32. Denis shares several similarities to the SOUNDBITE backdoor and has been used in conjunction with the Goopy backdoor.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1012
Query Registry

Denis queries the Registry for keys and values.

T1016
System Network Configuration Discovery

Denis uses ipconfig to gather the IP address from the system.

T1027
Obfuscated Files or Information

Denis obfuscates its code and encrypts the API names.

T1027.010
Command Obfuscation

Denis has encoded its PowerShell commands in Base64.

T1033
System Owner/User Discovery

Denis enumerates and collects the username from the victim’s machine.

T1055.012
Process Hollowing

Denis performed process hollowing through the API calls CreateRemoteThread, ResumeThread, and Wow64SetThreadContext.

T1059.001
PowerShell

Denis has a version written in PowerShell.

T1059.003
Windows Command Shell

Denis can launch a remote shell to execute arbitrary commands on the victim’s machine.

T1070.004
File Deletion

Denis has a command to delete files from the victim’s machine.

T1071.004
DNS

Denis has used DNS tunneling for C2 communications.

T1082
System Information Discovery

Denis collects OS information and the computer name from the victim’s machine.

T1083
File and Directory Discovery

Denis has several commands to search directories for files.

T1105
Ingress Tool Transfer

Denis deploys additional backdoors and hacking tools to the system.

T1106
Native API

Denis used the IsDebuggerPresent, OutputDebugString, and SetLastError APIs to avoid debugging. Denis used GetProcAddress and LoadLibrary to dynamically resolve APIs. Denis also used the Wow64SetThreadContext API as part of a process hollowing process.

T1132.001
Standard Encoding

Denis encodes the data sent to the server in Base64.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cybereason Oceanlotus May 2017 Open source
    Dahan, A. (2017, May 24). OPERATION COBALT KITTY: A LARGE-SCALE APT IN ASIA CARRIED OUT BY THE OCEANLOTUS GROUP. Retrieved November 5, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.