Malware.View on attack.mitre.org
FELIXROOT is a backdoor that has been used to target Ukrainian victims.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
FELIXROOT queries the Registry for specific keys for potential privilege escalation and proxy information. FELIXROOT has also used WMI to query the Windows Registry. |
| T1016 System Network Configuration Discovery |
FELIXROOT collects information about the network including the IP address and DHCP server. |
| T1027.013 Encrypted/Encoded File |
FELIXROOT encrypts strings in the backdoor using a custom XOR algorithm. |
| T1033 System Owner/User Discovery |
FELIXROOT collects the username from the victim’s machine. |
| T1047 Windows Management Instrumentation |
FELIXROOT uses WMI to query the Windows Registry. |
| T1057 Process Discovery |
FELIXROOT collects a list of running processes. |
| T1059.003 Windows Command Shell |
FELIXROOT executes batch scripts on the victim’s machine, and can launch a reverse shell for command execution. |
| T1070.004 File Deletion |
FELIXROOT deletes the .LNK file from the startup directory as well as the dropper components. |
| T1071.001 Web Protocols |
FELIXROOT uses HTTP and HTTPS to communicate with the C2 server. |
| T1082 System Information Discovery |
FELIXROOT collects the victim’s computer name, processor architecture, OS version, and system type. |
| T1105 Ingress Tool Transfer |
FELIXROOT downloads and uploads files to and from the victim’s machine. |
| T1112 Modify Registry |
FELIXROOT deletes the Registry key |
| T1124 System Time Discovery |
FELIXROOT gathers the time zone information from the victim’s machine. |
| T1218.011 Rundll32 |
FELIXROOT uses Rundll32 for executing the dropper program. |
| T1518.001 Security Software Discovery |
FELIXROOT checks for installed security software like antivirus and firewall. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.