ATT&CKReferencesESET Zebrocy May 2019

ESET Zebrocy May 2019

ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareZebrocy

Zebrocy executes the reg query command to obtain information in the Registry.

T1016
System Network Configuration Discovery
MalwareZebrocy

Zebrocy runs the ipconfig /all command.

T1049
System Network Connections Discovery
MalwareZebrocy

Zebrocy uses netstat -aon to gather network connection information.

T1057
Process Discovery
MalwareZebrocy

Zebrocy uses the tasklist and wmic process get Capture, ExecutablePath commands to gather the processes running on the system.

T1059.003
Windows Command Shell
MalwareZebrocy

Zebrocy uses cmd.exe to execute commands on the system.

T1070.004
File Deletion
MalwareZebrocy

Zebrocy has a command to delete files and directories.

T1071.001
Web Protocols
MalwareZebrocy

Zebrocy uses HTTP for C2.

T1071.003
Mail Protocols
MalwareZebrocy

Zebrocy uses SMTP and POP3 for C2.

T1082
System Information Discovery
MalwareZebrocy

Zebrocy collects the OS version and computer name. Zebrocy also runs the systeminfo command to gather system information.

T1083
File and Directory Discovery
MalwareZebrocy

Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the echo %APPDATA% command to list the contents of the directory. Zebrocy can obtain the current execution path as well as perform drive enumeration.

T1105
Ingress Tool Transfer
MalwareZebrocy

Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload.

T1113
Screen Capture
MalwareZebrocy

A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format.

T1119
Automated Collection
MalwareZebrocy

Zebrocy scans the system and automatically collects files with the following extensions: .doc, .docx, ,.xls, .xlsx, .pdf, .pptx, .rar, .zip, .jpg, .jpeg, .bmp, .tiff, .kum, .tlg, .sbx, .cr, .hse, .hsf, and .lhz.

T1218.011
Rundll32
GroupAPT28

APT28 executed CHOPSTICK by using rundll32 commands such as rundll32.exe “C:\Windows\twain_64.dll”. APT28 also executed a .dll for a first stage dropper using rundll32.exe. An APT28 loader Trojan saved a batch script that uses rundll32 to execute a DLL payload.

T1546.015
Component Object Model Hijacking
GroupAPT28

APT28 has used COM hijacking for persistence by replacing the legitimate MMDeviceEnumerator object with a payload.

T1547.001
Registry Run Keys / Startup Folder
MalwareZebrocy

Zebrocy creates an entry in a Registry Run key for the malware to execute on startup.

T1555.003
Credentials from Web Browsers
MalwareZebrocy

Zebrocy has the capability to upload dumper tools that extract credentials from web browsers and store them in database files.

T1573.001
Symmetric Cryptography
GroupAPT28

APT28 installed a Delphi backdoor that used a custom algorithm for C2 communications.

T1573.002
Asymmetric Cryptography
MalwareZebrocy

Zebrocy uses SSL and AES ECB for encrypting C2 communications.

T1598.003
Spearphishing Link
GroupAPT28

APT28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites.

T1680
Local Storage Discovery
MalwareZebrocy

Zebrocy collects the serial number for the storage volume C:\.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.