EvilBunny

S0396

Malware.View on attack.mitre.org

About this malware

EvilBunny is a C++ malware sample observed since 2011 that was designed to be a execution platform for Lua scripts.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1047
Windows Management Instrumentation

EvilBunny has used WMI to gather information about the system.

T1053.005
Scheduled Task

EvilBunny has executed commands via scheduled tasks.

T1057
Process Discovery

EvilBunny has used EnumProcesses() to identify how many process are running in the environment.

T1059.003
Windows Command Shell

EvilBunny has an integrated scripting engine to download and execute Lua scripts.

T1059.011
Lua

EvilBunny has used Lua scripts to execute payloads.

T1070.004
File Deletion

EvilBunny has deleted the initial dropper after running through the environment checks.

T1071.001
Web Protocols

EvilBunny has executed C2 commands directly via HTTP.

T1105
Ingress Tool Transfer

EvilBunny has downloaded additional Lua scripts from the C2.

T1106
Native API

EvilBunny has used various API calls as part of its checks to see if the malware is running in a sandbox.

T1124
System Time Discovery

EvilBunny has used the API calls NtQuerySystemTime, GetSystemTimeAsFileTime, and GetTickCount to gather time metrics as part of its checks to see if the malware is running in a sandbox.

T1203
Exploitation for Client Execution

EvilBunny has exploited CVE-2011-4369, a vulnerability in the PRC component in Adobe Reader.

T1497.001
System Checks

EvilBunny's dropper has checked the number of processes and the length and strings of its own file name to identify if the malware is in a sandbox environment.

T1497.003
Time Based Checks

EvilBunny has used time measurements from 3 different APIs before and after performing sleep operations to check and abort if the malware is running in a sandbox.

T1518.001
Security Software Discovery

EvilBunny has been observed querying installed antivirus software.

T1547.001
Registry Run Keys / Startup Folder

EvilBunny has created Registry keys for persistence in [HKLM|HKCU]\…\CurrentVersion\Run.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Cyphort EvilBunny Dec 2014 Open source
    Marschalek, M.. (2014, December 16). EvilBunny: Malware Instrumented By Lua. Retrieved June 28, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.