Malware.View on attack.mitre.org
LP-Notes is a C/C++ Windows credential stealer used by MuddyWater. LP-Notes was named after the `lp-notes.txt` file that is used to store stolen credentials.
| Technique | Procedure example |
|---|---|
| T1027.007 Dynamic API Resolution |
LP-Notes has dynamically resolved API functions during the C runtime startup. |
| T1027.013 Encrypted/Encoded File |
LP-Notes has used a custom addition-based function and a string stacking function for string encryption. |
| T1056.002 GUI Input Capture |
LP-Notes has displayed a fake Windows Security dialog box to prompt for Windows credentials. |
| T1057 Process Discovery |
LP-Notes has searched for the process taskhostw.exe. |
| T1059.001 PowerShell |
LP-Notes has been downloaded and executed by PowerShell’s`Invoke-WebRequest` and `Invoke-Expression` cmdlets. |
| T1074.001 Local Data Staging |
LP-Notes has stored collected credentials in ` C:\Users\Public\Downloads\lp-notes.txt`. |
| T1078 Valid Accounts |
LP-Notes has used stolen Windows credentials to log in as the users. |
| T1106 Native API |
LP-Notes has used the `ImpersonateLoggedOnUser` API to impersonate the security context of the taskhostw.exe process. Additionally, LP-Notes has also used the `CredUIPromptForWindowsCredentialsW` API to obtain Windows credentials. |
| T1134.001 Token Impersonation/Theft |
LP-Notes has impersonated the security context of the taskhostw.exe process via the `ImpersonateLoggedOnUser` API. |
| T1140 Deobfuscate/Decode Files or Information |
LP-Notes has decrypted strings with lengths ranging from 15 to 19 characters using the same decryption key for each string. |
| T1560 Archive Collected Data |
LP-Notes has encrypted collected credentials using AES-CBC from the CNG API and the key ED15C8344B45DAED1E0578F8BC1A32411812C61F4CB45D89B107287DE0E09FFC |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.