Malware.View on attack.mitre.org
EvilBunny is a C++ malware sample observed since 2011 that was designed to be a execution platform for Lua scripts.
| Technique | Procedure example |
|---|---|
| T1047 Windows Management Instrumentation |
EvilBunny has used WMI to gather information about the system. |
| T1053.005 Scheduled Task |
EvilBunny has executed commands via scheduled tasks. |
| T1057 Process Discovery |
EvilBunny has used EnumProcesses() to identify how many process are running in the environment. |
| T1059.003 Windows Command Shell |
EvilBunny has an integrated scripting engine to download and execute Lua scripts. |
| T1059.011 Lua |
EvilBunny has used Lua scripts to execute payloads. |
| T1070.004 File Deletion |
EvilBunny has deleted the initial dropper after running through the environment checks. |
| T1071.001 Web Protocols |
EvilBunny has executed C2 commands directly via HTTP. |
| T1105 Ingress Tool Transfer |
EvilBunny has downloaded additional Lua scripts from the C2. |
| T1106 Native API |
EvilBunny has used various API calls as part of its checks to see if the malware is running in a sandbox. |
| T1124 System Time Discovery |
EvilBunny has used the API calls NtQuerySystemTime, GetSystemTimeAsFileTime, and GetTickCount to gather time metrics as part of its checks to see if the malware is running in a sandbox. |
| T1203 Exploitation for Client Execution |
EvilBunny has exploited CVE-2011-4369, a vulnerability in the PRC component in Adobe Reader. |
| T1497.001 System Checks |
EvilBunny's dropper has checked the number of processes and the length and strings of its own file name to identify if the malware is in a sandbox environment. |
| T1497.003 Time Based Checks |
EvilBunny has used time measurements from 3 different APIs before and after performing sleep operations to check and abort if the malware is running in a sandbox. |
| T1518.001 Security Software Discovery |
EvilBunny has been observed querying installed antivirus software. |
| T1547.001 Registry Run Keys / Startup Folder |
EvilBunny has created Registry keys for persistence in |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.