Epic

S0091

Malware.View on attack.mitre.org

About this malware

Epic is a backdoor that has been used by Turla.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1007
System Service Discovery

Epic uses the tasklist /svc command to list the services on the system.

T1012
Query Registry

Epic uses the rem reg query command to obtain values from Registry keys.

T1016
System Network Configuration Discovery

Epic uses the nbtstat -n and nbtstat -s commands on the victim’s machine.

T1018
Remote System Discovery

Epic uses the net view command on the victim’s machine.

T1027
Obfuscated Files or Information

Epic heavily obfuscates its code to make analysis more difficult.

T1033
System Owner/User Discovery

Epic collects the user name from the victim’s machine.

T1049
System Network Connections Discovery

Epic uses the net use, net session, and netstat commands to gather information on network connections.

T1055.011
Extra Window Memory Injection

Epic has overwritten the function pointer in the extra window memory of Explorer's Shell_TrayWnd in order to execute malicious code in the context of the explorer.exe process.

T1057
Process Discovery

Epic uses the tasklist /v command to obtain a list of processes.

T1069.001
Local Groups

Epic gathers information on local group names.

T1070.004
File Deletion

Epic has a command to delete a file from the machine.

T1071.001
Web Protocols

Epic uses HTTP and HTTPS for C2 communications.

T1082
System Information Discovery

Epic collects the OS version, hardware information, computer name, available system memory status, and system and user language settings.

T1083
File and Directory Discovery

Epic recursively searches for all .doc files on the system and collects a directory listing of the Desktop, %TEMP%, and %WINDOWS%\Temp directories.

T1087.001
Local Account

Epic gathers a list of all user accounts, privilege classes, and time of last logon.

View all 22 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Kaspersky Turla Open source
    Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.