ATT&CKReferencesFireEye SUNBURST Additional Details Dec 2020

FireEye SUNBURST Additional Details Dec 2020

Stephen Eckels, Jay Smith, William Ballenthin. (2020, December 24). SUNBURST Additional Technical Details. Retrieved January 6, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1001.002
Steganography
MalwareSUNBURST

SUNBURST C2 data attempted to appear as benign XML related to .NET assemblies or as a faux JSON blob.

T1518.001
Security Software Discovery
MalwareSUNBURST

SUNBURST checked for a variety of antivirus/endpoint detection agents prior to execution.

T1685
Disable or Modify Tools
MalwareSUNBURST

SUNBURST attempted to disable software security services following checks against a FNV-1a + XOR hashed hardcoded blocklist.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.