H1N1 is a malware variant that has been distributed via a campaign using VBA macros to infect victims. Although it initially had only loader capabilities, it has evolved to include information-stealing functionality. (Citation: Cisco H1N1 Part 1)
ID: S0132
Platforms: Windows
Version: 1.2
Created: 31 May 2017
Last Modified: 30 Mar 2020

Techniques Used

Domain ID Name Use
Enterprise T1548 .002 Abuse Elevation Control Mechanism: Bypass User Account Control

H1N1 bypasses user access control by using a DLL hijacking vulnerability in the Windows Update Standalone Installer (wusa.exe).(Citation: Cisco H1N1 Part 2)

Enterprise T1059 .003 Command and Scripting Interpreter: Windows Command Shell

H1N1 kills and disables services by using cmd.exe.(Citation: Cisco H1N1 Part 2)

Enterprise T1555 .003 Credentials from Password Stores: Credentials from Web Browsers

H1N1 dumps usernames and passwords from Firefox, Internet Explorer, and Outlook.(Citation: Cisco H1N1 Part 2)

Enterprise T1573 .001 Encrypted Channel: Symmetric Cryptography

H1N1 encrypts C2 traffic using an RC4 key.(Citation: Cisco H1N1 Part 2)

Enterprise T1562 .001 Impair Defenses: Disable or Modify Tools

H1N1 kills and disables services for Windows Security Center, and Windows Defender.(Citation: Cisco H1N1 Part 2)

.004 Impair Defenses: Disable or Modify System Firewall

H1N1 kills and disables services for Windows Firewall.(Citation: Cisco H1N1 Part 2)

Enterprise T1027 .002 Obfuscated Files or Information: Software Packing

H1N1 uses a custom packing algorithm.(Citation: Cisco H1N1 Part 1)

