ATT&CKReferencesCrowdStrike Putter Panda

CrowdStrike Putter Panda

Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

Open the source

Techniques1

Groups1

Software4

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupPutter Panda

Droppers used by Putter Panda use RC4 or a 16-byte XOR key consisting of the bytes 0xA0 – 0xAF to obfuscate payloads.

T1055.001
Dynamic-link Library Injection
GroupPutter Panda

An executable dropped onto victims by Putter Panda aims to inject the specified DLL into a process that would normally be accessing the network, including Outlook Express (msinm.exe), Outlook (outlook.exe), Internet Explorer (iexplore.exe), and Firefox (firefox.exe).

T1057
Process Discovery
Malware4H RAT

4H RAT has the capability to obtain a listing of running processes (including loaded modules).

T1059.003
Windows Command Shell
Malware4H RAT

4H RAT has the capability to create a remote shell.

T1059.003
Windows Command Shell
Malwarehttpclient

httpclient opens cmd.exe on the victim.

T1070.004
File Deletion
Malwarepngdowner

pngdowner deletes content from C2 communications that was saved to the user's temporary directory.

T1070.006
Timestomp
Malware3PARA RAT

3PARA RAT has a command to set certain attributes such as creation/modification timestamps on files.

T1071.001
Web Protocols
Malware3PARA RAT

3PARA RAT uses HTTP for command and control.

T1071.001
Web Protocols
Malware4H RAT

4H RAT uses HTTP for command and control.

T1071.001
Web Protocols
Malwarepngdowner

pngdowner uses HTTP for command and control.

T1071.001
Web Protocols
Malwarehttpclient

httpclient uses HTTP for command and control.

T1082
System Information Discovery
Malware4H RAT

4H RAT sends an OS version identifier in its beacons.

T1083
File and Directory Discovery
Malware3PARA RAT

3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory.

T1083
File and Directory Discovery
Malware4H RAT

4H RAT has the capability to obtain file and directory listings.

T1547.001
Registry Run Keys / Startup Folder
GroupPutter Panda

A dropper used by Putter Panda installs itself into the ASEP Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run with a value named McUpdate.

T1552.001
Credentials In Files
Malwarepngdowner

If an initial connectivity check fails, pngdowner attempts to extract proxy details and credentials from Windows Protected Storage and from the IE Credentials Store. This allows the adversary to use the proxy credentials for subsequent requests if they enable outbound HTTP access.

T1573.001
Symmetric Cryptography
Malwarehttpclient

httpclient encrypts C2 content with XOR using a single byte, 0x12.

T1573.001
Symmetric Cryptography
Malware4H RAT

4H RAT obfuscates C2 communication using a 1-byte XOR with the key 0xBE.

T1573.001
Symmetric Cryptography
Malware3PARA RAT

3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode with a key derived from the MD5 hash of the string HYF54&%9&jkMCXuiS. 3PARA RAT will use an 8-byte XOR key derived from the string HYF54&%9&jkMCXuiS if the DES decoding fails

T1685
Disable or Modify Tools
GroupPutter Panda

Malware used by Putter Panda attempts to terminate processes corresponding to two components of Sophos Anti-Virus (SAVAdminService.exe and SavService.exe).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.