Orz is a custom JavaScript backdoor used by Leviathan. It was observed being used in 2014 as well as in August 2017 when it was dropped by Microsoft Publisher files. [1] [2]

ID: S0229
Associated Software: Orz

Platforms: Windows

Version: 1.0

Associated Software Descriptions


Techniques Used

EnterpriseT1059Command-Line InterfaceOrz can execute shell commands.[1]
EnterpriseT1083File and Directory DiscoveryOrz can gather victim drive information.[1]
EnterpriseT1070Indicator Removal on HostOrz can overwrite Registry settings to reduce its visibility on the victim.[1]
EnterpriseT1027Obfuscated Files or InformationSome Orz strings are base64 encoded, such as the embedded DLL known as MockDll.[1]
EnterpriseT1057Process DiscoveryOrz can gather a process list from the victim.[1]
EnterpriseT1093Process HollowingSome Orz versions have an embedded DLL known as MockDll that uses process hollowing and Regsvr32 to execute another payload.[1]
EnterpriseT1117Regsvr32Some Orz versions have an embedded DLL known as MockDll that uses Process Hollowing and regsvr32 to execute another payload.[1]
EnterpriseT1105Remote File CopyOrz can download files onto the victim.[1]
EnterpriseT1064ScriptingOrz can execute commands with script as well as execute JavaScript.[1]
EnterpriseT1082System Information DiscoveryOrz can gather the victim OS version and whether it is 64 or 32 bit.[1]
EnterpriseT1016System Network Configuration DiscoveryOrz can gather victim proxy information.[1]
EnterpriseT1102Web ServiceOrz has used Technet and Pastebin web pages for command and control.[1]


Groups that use this software: