ATT&CKReferencesTalos Rocke August 2018

Talos Rocke August 2018

Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1018
Remote System Discovery
GroupRocke

Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them.

T1027.002
Software Packing
GroupRocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1036.005
Match Legitimate Resource Name or Location
GroupRocke

Rocke has used shell scripts which download mining executables and saves them with the filename "java".

T1046
Network Service Discovery
GroupRocke

Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers.

T1053.003
Cron
GroupRocke

Rocke installed a cron job that downloaded and executed files from the C2.

T1055.002
Portable Executable Injection
GroupRocke

Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe.

T1059.004
Unix Shell
GroupRocke

Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware.

T1071
Application Layer Protocol
GroupRocke

Rocke issued wget requests from infected systems to the C2.

T1102
Web Service
GroupRocke

Rocke has used Pastebin, Gitee, and GitLab for Command and Control.

T1105
Ingress Tool Transfer
GroupRocke

Rocke used malware to download additional malicious files to the target system.

T1140
Deobfuscate/Decode Files or Information
GroupRocke

Rocke has extracted tar.gz files after downloading them from a C2 server.

T1190
Exploit Public-Facing Application
GroupRocke

Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware.

T1496.001
Compute Hijacking
GroupRocke

Rocke has distributed cryptomining malware.

T1518.001
Security Software Discovery
GroupRocke

Rocke used scripts which detected and uninstalled antivirus software.

T1547.001
Registry Run Keys / Startup Folder
GroupRocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1564.001
Hidden Files and Directories
GroupRocke

Rocke downloaded a file "libprocesshider", which could hide files on the target system.

T1685
Disable or Modify Tools
GroupRocke

Rocke used scripts which detected and uninstalled antivirus software.

T1686
Disable or Modify System Firewall
GroupRocke

Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.