Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
JHUHUGIT tests if it can reach its C2 server by first attempting a direct connection, and if it fails, obtaining proxy settings and sending the connection through a proxy, and finally injecting code into a running browser if the proxy method fails. |
| T1016 System Network Configuration Discovery |
A JHUHUGIT variant gathers network interface card information. |
| T1027.013 Encrypted/Encoded File |
Many strings in JHUHUGIT are obfuscated with a XOR algorithm. |
| T1037.001 Logon Script (Windows) |
JHUHUGIT has registered a Windows shell script under the Registry key |
| T1053.005 Scheduled Task |
JHUHUGIT has registered itself as a scheduled task to run each time the current user logs in. |
| T1055 Process Injection |
JHUHUGIT performs code injection injecting its own functions to browser processes. |
| T1057 Process Discovery |
JHUHUGIT obtains a list of running processes on the victim. |
| T1059.003 Windows Command Shell |
JHUHUGIT uses a .bat file to execute a .dll. |
| T1068 Exploitation for Privilege Escalation |
JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges. |
| T1070.004 File Deletion |
The JHUHUGIT dropper can delete itself from the victim. Another JHUHUGIT variant has the capability to delete specified files. |
| T1071.001 Web Protocols |
JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS. |
| T1105 Ingress Tool Transfer |
JHUHUGIT can retrieve an additional payload from its C2 server. JHUHUGIT has a command to download files to the victim’s machine. |
| T1113 Screen Capture |
A JHUHUGIT variant takes screenshots by simulating the user pressing the "Take Screenshot" key (VK_SCREENSHOT), accessing the screenshot saved in the clipboard, and converting it to a JPG image. |
| T1115 Clipboard Data |
A JHUHUGIT variant accesses a screenshot saved in the clipboard and converts it to a JPG image. |
| T1132.001 Standard Encoding |
A JHUHUGIT variant encodes C2 POST data base64. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.