ESET. (2016, October). En Route with Sednit - Part 3: A Mysterious Downloader. Retrieved November 21, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareDowndelph | Downdelph inserts pseudo-random characters between each original character during encoding of C2 network requests, making it difficult to write signatures on them. |
| T1014 Rootkit |
MalwareHIDEDRV | HIDEDRV is a rootkit that hides certain operating system artifacts. |
| T1055.001 Dynamic-link Library Injection |
MalwareHIDEDRV | HIDEDRV injects a DLL for Downdelph into the explorer.exe process. |
| T1105 Ingress Tool Transfer |
MalwareDowndelph | After downloading its main config file, Downdelph downloads multiple payloads from C2 servers. |
| T1542.003 Bootkit |
GroupAPT28 | APT28 has deployed a bootkit along with Downdelph to ensure its persistence on the victim. The bootkit shares code with some variants of BlackEnergy. |
| T1548.002 Bypass User Account Control |
MalwareDowndelph | Downdelph bypasses UAC to escalate privileges by using a custom “RedirectEXE” shim database. |
| T1573.001 Symmetric Cryptography |
MalwareDowndelph | Downdelph uses RC4 to encrypt C2 responses. |
| T1574.001 DLL |
MalwareDowndelph | Downdelph uses search order hijacking of the Windows executable sysprep.exe to escalate privileges. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.