ATT&CKReferencesESET Sednit Part 3

ESET Sednit Part 3

ESET. (2016, October). En Route with Sednit - Part 3: A Mysterious Downloader. Retrieved November 21, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareDowndelph

Downdelph inserts pseudo-random characters between each original character during encoding of C2 network requests, making it difficult to write signatures on them.

T1014
Rootkit
MalwareHIDEDRV

HIDEDRV is a rootkit that hides certain operating system artifacts.

T1055.001
Dynamic-link Library Injection
MalwareHIDEDRV

HIDEDRV injects a DLL for Downdelph into the explorer.exe process.

T1105
Ingress Tool Transfer
MalwareDowndelph

After downloading its main config file, Downdelph downloads multiple payloads from C2 servers.

T1542.003
Bootkit
GroupAPT28

APT28 has deployed a bootkit along with Downdelph to ensure its persistence on the victim. The bootkit shares code with some variants of BlackEnergy.

T1548.002
Bypass User Account Control
MalwareDowndelph

Downdelph bypasses UAC to escalate privileges by using a custom “RedirectEXE” shim database.

T1573.001
Symmetric Cryptography
MalwareDowndelph

Downdelph uses RC4 to encrypt C2 responses.

T1574.001
DLL
MalwareDowndelph

Downdelph uses search order hijacking of the Windows executable sysprep.exe to escalate privileges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.