ATT&CKReferencesESET Turla PowerShell May 2019

ESET Turla PowerShell May 2019

Faou, M. and Dumont R.. (2019, May 29). A dive into Turla PowerShell usage. Retrieved June 14, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupTurla

Turla RPC backdoors can upload files from victim machines.

T1012
Query Registry
GroupTurla

Turla surveys a system upon check-in to discover information in the Windows Registry with the reg query command. Turla has also retrieved PowerShell payloads hidden in Registry keys as well as checking keys associated with null session named pipes .

T1016
System Network Configuration Discovery
GroupTurla

Turla surveys a system upon check-in to discover network configuration details using the arp -a, nbtstat -n, net config, ipconfig /all, and route commands, as well as NBTscan. Turla RPC backdoors have also retrieved registered RPC interface information from process memory.

T1025
Data from Removable Media
GroupTurla

Turla RPC backdoors can collect files from USB thumb drives.

T1027
Obfuscated Files or Information
MalwarePowerStallion

PowerStallion uses a XOR cipher to encrypt command output written to its OneDrive C2 server.

T1027.010
Command Obfuscation
GroupTurla

Turla has used encryption (including salted 3DES via PowerSploit's Out-EncryptedScript.ps1), random variable names, and base64 encoding to obfuscate PowerShell commands and payloads.

T1027.011
Fileless Storage
GroupTurla

Turla has used the Registry to store encrypted and encoded payloads.

T1049
System Network Connections Discovery
GroupTurla

Turla surveys a system upon check-in to discover active local network connections using the netstat -an, net use, net file, and net session commands. Turla RPC backdoors have also enumerated the IPv4 TCP connection table via the GetTcpTable2 API call.

T1055
Process Injection
GroupTurla

Turla has also used PowerSploit's Invoke-ReflectivePEInjection.ps1 to reflectively load a PowerShell payload into a random process on the victim system.

T1057
Process Discovery
GroupTurla

Turla surveys a system upon check-in to discover running processes using the tasklist /v command. Turla RPC backdoors have also enumerated processes associated with specific open ports or named pipes.

T1057
Process Discovery
MalwarePowerStallion

PowerStallion has been used to monitor process lists.

T1059.001
PowerShell
MalwarePowerStallion

PowerStallion uses PowerShell loops to iteratively check for available commands in its OneDrive C2 server.

T1059.001
PowerShell
GroupTurla

Turla has used PowerShell to execute commands/scripts, in some cases via a custom executable or code from Empire's PSInject. Turla has also used PowerShell scripts to load and execute malware in memory.

T1059.003
Windows Command Shell
GroupTurla

Turla RPC backdoors have used cmd.exe to execute commands.

T1070.006
Timestomp
MalwarePowerStallion

PowerStallion modifies the MAC times of its local log files to match that of the victim's desktop.ini file.

T1083
File and Directory Discovery
GroupTurla

Turla surveys a system upon check-in to discover files in specific locations on the hard disk %TEMP% directory, the current user's desktop, the Program Files directory, and Recent. Turla RPC backdoors have also searched for files matching the lPH*.dll pattern.

T1090
Proxy
GroupTurla

Turla RPC backdoors have included local UPnP RPC proxies.

T1102.002
Bidirectional Communication
MalwarePowerStallion

PowerStallion uses Microsoft OneDrive as a C2 server via a network drive mapped with net use.

T1106
Native API
GroupTurla

Turla and its RPC backdoors have used APIs calls for various tasks related to subverting AMSI and accessing then executing commands through RPC and/or named pipes.

T1112
Modify Registry
GroupTurla

Turla has modified Registry values to store payloads.

T1134.002
Create Process with Token
GroupTurla

Turla RPC backdoors can impersonate or steal process tokens before executing commands.

T1140
Deobfuscate/Decode Files or Information
GroupTurla

Turla has used a custom decryption routine, which pulls key and salt values from other artifacts such as a WMI filter or PowerShell Profile, to decode encrypted PowerShell payloads.

T1546.003
Windows Management Instrumentation Event Subscription
GroupTurla

Turla has used WMI event filters and consumers to establish persistence.

T1546.013
PowerShell Profile
GroupTurla

Turla has used PowerShell profiles to maintain persistence on an infected machine.

T1570
Lateral Tool Transfer
GroupTurla

Turla RPC backdoors can be used to transfer files to/from victim machines on the local network.

T1685
Disable or Modify Tools
GroupTurla

Turla has used a AMSI bypass, which patches the in-memory amsi.dll, in PowerShell scripts to bypass Windows antimalware products.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.