ATT&CKSoftwareFinal1stspy

Final1stspy

S0355

Malware.View on attack.mitre.org

About this malware

Final1stspy is a dropper family that has been used to deliver DOGCALL.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027
Obfuscated Files or Information

Final1stspy obfuscates strings with base64 encoding.

T1057
Process Discovery

Final1stspy obtains a list of running processes.

T1071.001
Web Protocols

Final1stspy uses HTTP for C2.

T1082
System Information Discovery

Final1stspy obtains victim Microsoft Windows version information and CPU architecture.

T1140
Deobfuscate/Decode Files or Information

Final1stspy uses Python code to deobfuscate base64-encoded strings.

T1547.001
Registry Run Keys / Startup Folder

Final1stspy creates a Registry Run key to establish persistence.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit 42 Nokki Oct 2018 Open source
    Grunzweig, J. (2018, October 01). NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT. Retrieved November 5, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.