HermeticWizard
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1110 | .001 | Brute Force: Password Guessing |
HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares.(Citation: ESET Hermetic Wizard March 2022) |
Enterprise | T1059 | .003 | Command and Scripting Interpreter: Windows Command Shell |
HermeticWizard can use `cmd.exe` for execution on compromised hosts.(Citation: ESET Hermetic Wizard March 2022) |
Enterprise | T1070 | .001 | Indicator Removal: Clear Windows Event Logs |
HermeticWizard has the ability to use `wevtutil cl system` to clear event logs.(Citation: ESET Hermetic Wizard March 2022) |
Enterprise | T1559 | .001 | Inter-Process Communication: Component Object Model |
HermeticWizard can execute files on remote machines using DCOM.(Citation: ESET Hermetic Wizard March 2022) |
Enterprise | T1036 | .005 | Masquerading: Match Legitimate Name or Location |
HermeticWizard has been named `exec_32.dll` to mimic a legitimate MS Outlook .dll.(Citation: ESET Hermetic Wizard March 2022) |
Enterprise | T1027 | .013 | Obfuscated Files or Information: Encrypted/Encoded File |
HermeticWizard has the ability to encrypt PE files with a reverse XOR loop.(Citation: ESET Hermetic Wizard March 2022) |
Enterprise | T1021 | .002 | Remote Services: SMB/Windows Admin Shares |
HermeticWizard can use a list of hardcoded credentials to to authenticate via NTLMSSP to the SMB shares on remote systems.(Citation: ESET Hermetic Wizard March 2022) |
Enterprise | T1553 | .002 | Subvert Trust Controls: Code Signing |
HermeticWizard has been signed by valid certificates assigned to Hermetica Digital.(Citation: ESET Hermetic Wizard March 2022) |
Enterprise | T1218 | .010 | System Binary Proxy Execution: Regsvr32 |
HermeticWizard has used `regsvr32.exe /s /i` to execute malicious payloads.(Citation: ESET Hermetic Wizard March 2022) |
.011 | System Binary Proxy Execution: Rundll32 |
HermeticWizard has the ability to create a new process using `rundll32`.(Citation: ESET Hermetic Wizard March 2022) |
||
Enterprise | T1569 | .002 | System Services: Service Execution |
HermeticWizard can use `OpenRemoteServiceManager` to create a service.(Citation: ESET Hermetic Wizard March 2022) |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.