TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Tackling Gootkit's Traps

2018-07-11 · Read original ↗

ATT&CK techniques detected

2 predictions
T1497.001System Checks
96%
“sandbox " - compare computer name to " sandbox " / " 7silvia " - hkey _ local _ machine \ hardware \ description \ system \ systembiosversion " compare with ami, virtualbox, bochs, intel 640000, 55274 - 640 - 2673064 - 23950, and other serials after patching a virtual machine and…”
T1497.001System Checks
94%
“is the function making all the environment checks. we ’ ll have to check each condition that leads to a trap and make sure to change the environment ( or patch the binary ) in a way that would bypass the trap. figure 8 shows a code snippet from the sub _ 409ae2 function. note tha…”

Summary

Gootkit malware uses misleading code to hinder manual research and automated analysis.