PyDCrypt

S1032

Malware.View on attack.mitre.org

About this malware

PyDCrypt is malware written in Python designed to deliver DCSrv. It has been used by Moses Staff since at least September 2021, with each sample tailored for its intended victim organization.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

PyDCrypt has been compiled and encrypted with PyInstaller, specifically using the --key flag during the build phase.

T1033
System Owner/User Discovery

PyDCrypt has probed victim machines with whoami and has collected the username from the machine.

T1036.005
Match Legitimate Resource Name or Location

PyDCrypt has dropped DCSrv under the `svchost.exe` name to disk.

T1047
Windows Management Instrumentation

PyDCrypt has attempted to execute with WMIC.

T1049
System Network Connections Discovery

PyDCrypt has used netsh to find RPC connections on remote machines.

T1059.001
PowerShell

PyDCrypt has attempted to execute with PowerShell.

T1059.003
Windows Command Shell

PyDCrypt has used `cmd.exe` for execution.

T1059.006
Python

PyDCrypt, along with its functions, is written in Python.

T1070.004
File Deletion

PyDCrypt will remove all created artifacts such as dropped executables.

T1140
Deobfuscate/Decode Files or Information

PyDCrypt has decrypted and dropped the DCSrv payload to disk.

T1686
Disable or Modify System Firewall

PyDCrypt has modified firewall rules to allow incoming SMB, NetBIOS, and RPC connections using `netsh.exe` on remote machines.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Checkpoint MosesStaff Nov 2021 Open source
    Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.