Malware.View on attack.mitre.org
BOOSTWRITE is a loader crafted to be launched via abuse of the DLL search order of applications used by FIN7.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
BOOSTWRITE has encoded its payloads using a ChaCha stream cipher with a 256-bit key and 64-bit Initialization vector (IV) to evade detection. |
| T1129 Shared Modules |
BOOSTWRITE has used the DWriteCreateFactory() function to load additional modules. |
| T1140 Deobfuscate/Decode Files or Information |
BOOSTWRITE has used a a 32-byte long multi-XOR key to decode data inside its payload. |
| T1553.002 Code Signing |
BOOSTWRITE has been signed by a valid CA. |
| T1574.001 DLL |
BOOSTWRITE has exploited the loading of the legitimate Dwrite.dll file by actually loading the gdi library, which then loads the gdiplus library and ultimately loads the local Dwrite dll. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.