Malware.View on attack.mitre.org
PyDCrypt is malware written in Python designed to deliver DCSrv. It has been used by Moses Staff since at least September 2021, with each sample tailored for its intended victim organization.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
PyDCrypt has been compiled and encrypted with PyInstaller, specifically using the --key flag during the build phase. |
| T1033 System Owner/User Discovery |
PyDCrypt has probed victim machines with |
| T1036.005 Match Legitimate Resource Name or Location |
PyDCrypt has dropped DCSrv under the `svchost.exe` name to disk. |
| T1047 Windows Management Instrumentation |
PyDCrypt has attempted to execute with WMIC. |
| T1049 System Network Connections Discovery |
PyDCrypt has used netsh to find RPC connections on remote machines. |
| T1059.001 PowerShell |
PyDCrypt has attempted to execute with PowerShell. |
| T1059.003 Windows Command Shell |
PyDCrypt has used `cmd.exe` for execution. |
| T1059.006 Python |
PyDCrypt, along with its functions, is written in Python. |
| T1070.004 File Deletion |
PyDCrypt will remove all created artifacts such as dropped executables. |
| T1140 Deobfuscate/Decode Files or Information |
PyDCrypt has decrypted and dropped the DCSrv payload to disk. |
| T1686 Disable or Modify System Firewall |
PyDCrypt has modified firewall rules to allow incoming SMB, NetBIOS, and RPC connections using `netsh.exe` on remote machines. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.