StreamEx

S0142

Malware.View on attack.mitre.org

About this malware

StreamEx is a malware family that has been used by Deep Panda since at least 2015. In 2016, it was distributed via legitimate compromised Korean websites.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1027
Obfuscated Files or Information

StreamEx obfuscates some commands by using statically programmed fragments of strings when starting a DLL. It also uses a one-byte xor against 0x91 to encode configuration data.

T1057
Process Discovery

StreamEx has the ability to enumerate processes.

T1059.003
Windows Command Shell

StreamEx has the ability to remotely execute commands.

T1082
System Information Discovery

StreamEx has the ability to enumerate system information.

T1083
File and Directory Discovery

StreamEx has the ability to enumerate drive types.

T1112
Modify Registry

StreamEx has the ability to modify the Registry.

T1218.011
Rundll32

StreamEx uses rundll32 to call an exported function.

T1518.001
Security Software Discovery

StreamEx has the ability to scan for security tools such as firewalls and antivirus tools.

T1543.003
Windows Service

StreamEx establishes persistence by installing a new service pointing to its DLL and setting the service to auto-start.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cylance Shell Crew Feb 2017 Open source
    Cylance SPEAR Team. (2017, February 9). Shell Crew Variants Continue to Fly Under Big AV’s Radar. Retrieved February 15, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.