Fidelis Cybersecurity. (2016, February 29). The Turbo Campaign, Featuring Derusbi for 64-bit Linux. Retrieved March 2, 2016.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareDerusbi | Derusbi uses a backup communication method with an HTTP beacon. |
| T1033 System Owner/User Discovery |
MalwareDerusbi | A Linux version of Derusbi checks if the victim user ID is anything other than zero (normally used for root), and the malware will not execute if it does not have root privileges. Derusbi also gathers the username of the victim. |
| T1057 Process Discovery |
MalwareDerusbi | Derusbi collects current and parent process IDs. |
| T1059.004 Unix Shell |
MalwareDerusbi | Derusbi is capable of creating a remote Bash shell and executing commands. |
| T1070.004 File Deletion |
MalwareDerusbi | Derusbi is capable of deleting files. It has been observed loading a Linux Kernel Module (LKM) and then deleting it from the hard disk as well as overwriting the data with null bytes. |
| T1070.006 Timestomp |
MalwareDerusbi | The Derusbi malware supports timestomping. |
| T1082 System Information Discovery |
MalwareDerusbi | Derusbi gathers the name of the local host, version of GNU Compiler Collection (GCC), and the system information about the CPU, machine, and operating system. |
| T1083 File and Directory Discovery |
MalwareDerusbi | Derusbi is capable of obtaining directory, file, and drive listings. |
| T1095 Non-Application Layer Protocol |
MalwareDerusbi | Derusbi binds to a raw socket on a random source port between 31800 and 31900 for C2. |
| T1571 Non-Standard Port |
MalwareDerusbi | Derusbi has used unencrypted HTTP on port 443 for C2. |
| T1573.001 Symmetric Cryptography |
MalwareDerusbi | Derusbi obfuscates C2 traffic with variable 4-byte XOR keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.