Malware.View on attack.mitre.org
Daserf is a backdoor that has been used to spy on and steal from Japanese, South Korean, Russian, Singaporean, and Chinese victims. Researchers have identified versions written in both Visual C and Delphi.
| Technique | Procedure example |
|---|---|
| T1001.002 Steganography |
Daserf can use steganography to hide malicious code downloaded to the victim. |
| T1003.001 LSASS Memory |
Daserf leverages Mimikatz and Windows Credential Editor to steal credentials. |
| T1027 Obfuscated Files or Information |
Daserf uses encrypted Windows APIs and also encrypts data using the alternative base64+RC4 or the Caesar cipher. |
| T1027.002 Software Packing |
A version of Daserf uses the MPRESS packer. |
| T1027.005 Indicator Removal from Tools |
Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection. |
| T1036.005 Match Legitimate Resource Name or Location |
Daserf uses file and folder names related to legitimate programs in order to blend in, such as HP, Intel, Adobe, and perflogs. |
| T1056.001 Keylogging |
Daserf can log keystrokes. |
| T1059.003 Windows Command Shell |
Daserf can execute shell commands. |
| T1071.001 Web Protocols |
Daserf uses HTTP for C2. |
| T1105 Ingress Tool Transfer |
Daserf can download remote files. |
| T1113 Screen Capture |
Daserf can take screenshots. |
| T1132.001 Standard Encoding |
Daserf uses custom base64 encoding to obfuscate HTTP traffic. |
| T1553.002 Code Signing |
Some Daserf samples were signed with a stolen digital certificate. |
| T1560 Archive Collected Data |
Daserf hides collected data in password-protected .rar archives. |
| T1560.001 Archive via Utility |
Daserf hides collected data in password-protected .rar archives. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.