Fysbis
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1547 | .013 | Boot or Logon Autostart Execution: XDG Autostart Entries |
If executing without root privileges, Fysbis adds a `.desktop` configuration file to the user's `~/.config/autostart` directory.(Citation: Red Canary Netwire Linux 2022)(Citation: Fysbis Dr Web Analysis) |
Enterprise | T1059 | .004 | Command and Scripting Interpreter: Unix Shell |
Fysbis has the ability to create and execute commands in a remote shell for CLI.(Citation: Fysbis Palo Alto Analysis) |
Enterprise | T1543 | .002 | Create or Modify System Process: Systemd Service |
Fysbis has established persistence using a systemd service.(Citation: Fysbis Dr Web Analysis) |
Enterprise | T1132 | .001 | Data Encoding: Standard Encoding |
Fysbis can use Base64 to encode its C2 traffic.(Citation: Fysbis Dr Web Analysis) |
Enterprise | T1070 | .004 | Indicator Removal: File Deletion |
Fysbis has the ability to delete files.(Citation: Fysbis Dr Web Analysis) |
Enterprise | T1056 | .001 | Input Capture: Keylogging |
Fysbis can perform keylogging.(Citation: Fysbis Palo Alto Analysis) |
Enterprise | T1036 | .004 | Masquerading: Masquerade Task or Service |
Fysbis has masqueraded as the rsyncd and dbus-inotifier services.(Citation: Fysbis Dr Web Analysis) |
.005 | Masquerading: Match Legitimate Name or Location |
Fysbis has masqueraded as trusted software rsyncd and dbus-inotifier.(Citation: Fysbis Dr Web Analysis) |
||
Enterprise | T1027 | .013 | Obfuscated Files or Information: Encrypted/Encoded File |
Fysbis has been encrypted using XOR and RC4.(Citation: Fysbis Dr Web Analysis) |
References
- Bryan Lee and Rob Downs. (2016, February 12). A Look Into Fysbis: Sofacy’s Linux Backdoor. Retrieved September 10, 2017.
- Doctor Web. (2014, November 21). Linux.BackDoor.Fysbis.1. Retrieved December 7, 2017.
- TONY LAMBERT. (2022, June 7). Trapping the Netwire RAT on Linux. Retrieved September 28, 2023.
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.