ATT&CKReferencesProofpoint TA505 Mar 2018

Proofpoint TA505 Mar 2018

Proofpoint Staff. (2018, March 7). Leaked Ammyy Admin Source Code Turned into Malware. Retrieved May 28, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareFlawedAmmyy

FlawedAmmyy may obfuscate portions of the initial C2 handshake.

T1033
System Owner/User Discovery
MalwareFlawedAmmyy

FlawedAmmyy enumerates the current user during the initial infection.

T1047
Windows Management Instrumentation
MalwareFlawedAmmyy

FlawedAmmyy leverages WMI to enumerate anti-virus on the victim.

T1069.001
Local Groups
MalwareFlawedAmmyy

FlawedAmmyy enumerates the privilege level of the victim during the initial infection.

T1071.001
Web Protocols
MalwareFlawedAmmyy

FlawedAmmyy has used HTTP for C2.

T1082
System Information Discovery
MalwareFlawedAmmyy

FlawedAmmyy can collect the victim's operating system and computer name during the initial infection.

T1120
Peripheral Device Discovery
MalwareFlawedAmmyy

FlawedAmmyy will attempt to detect if a usable smart card is current inserted into a card reader.

T1204.001
Malicious Link
GroupTA505

TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1204.002
Malicious File
GroupTA505

TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1518.001
Security Software Discovery
MalwareFlawedAmmyy

FlawedAmmyy will attempt to detect anti-virus products during the initial infection.

T1566.001
Spearphishing Attachment
GroupTA505

TA505 has used spearphishing emails with malicious attachments to initially compromise victims.

T1573.001
Symmetric Cryptography
MalwareFlawedAmmyy

FlawedAmmyy has used SEAL encryption during the initial C2 handshake.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.