ATT&CKReferencesAccenture SNAKEMACKEREL Nov 2018

Accenture SNAKEMACKEREL Nov 2018

Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareZebrocy

Zebrocy's Delphi variant was packed with UPX.

T1027.013
Encrypted/Encoded File
GroupAPT28

APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4.

T1041
Exfiltration Over C2 Channel
MalwareZebrocy

Zebrocy has exfiltrated data to the designated C2 server using HTTP POST requests.

T1057
Process Discovery
MalwareZebrocy

Zebrocy uses the tasklist and wmic process get Capture, ExecutablePath commands to gather the processes running on the system.

T1059.003
Windows Command Shell
GroupAPT28

An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads.

T1071.001
Web Protocols
MalwareZebrocy

Zebrocy uses HTTP for C2.

T1082
System Information Discovery
MalwareZebrocy

Zebrocy collects the OS version and computer name. Zebrocy also runs the systeminfo command to gather system information.

T1083
File and Directory Discovery
MalwareZebrocy

Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the echo %APPDATA% command to list the contents of the directory. Zebrocy can obtain the current execution path as well as perform drive enumeration.

T1105
Ingress Tool Transfer
MalwareZebrocy

Zebrocy obtains additional code to execute on the victim's machine, including the downloading of a secondary payload.

T1105
Ingress Tool Transfer
GroupAPT28

APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant.

T1113
Screen Capture
MalwareZebrocy

A variant of Zebrocy captures screenshots of the victim’s machine in JPEG and BMP format.

T1132.001
Standard Encoding
MalwareZebrocy

Zebrocy has used URL/Percent Encoding on data exfiltrated via HTTP POST requests.

T1204.002
Malicious File
GroupAPT28

APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts.

T1547.001
Registry Run Keys / Startup Folder
MalwareZebrocy

Zebrocy creates an entry in a Registry Run key for the malware to execute on startup.

T1566.001
Spearphishing Attachment
GroupAPT28

APT28 sent spearphishing emails containing malicious Microsoft Office and RAR attachments.

T1680
Local Storage Discovery
MalwareZebrocy

Zebrocy collects the serial number for the storage volume C:\.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.