ATT&CKReferencesPalo Alto OilRig May 2016

Palo Alto OilRig May 2016

Falcone, R. and Lee, B.. (2016, May 26). The OilRig Campaign: Attacks on Saudi Arabian Organizations Deliver Helminth Backdoor. Retrieved May 3, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1007
System Service Discovery
GroupOilRig

OilRig has used sc query on a victim to gather information about services.

T1012
Query Registry
GroupOilRig

OilRig has used reg query “HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default” on a victim to query the Registry.

T1016
System Network Configuration Discovery
GroupOilRig

OilRig has run ipconfig /all on a victim.

T1027.013
Encrypted/Encoded File
MalwareHelminth

The Helminth config file is encrypted with RC4.

T1030
Data Transfer Size Limits
MalwareHelminth

Helminth splits data into chunks up to 23 bytes and sends the data in DNS queries to its C2 server.

T1033
System Owner/User Discovery
GroupOilRig

OilRig has run whoami on a victim.

T1049
System Network Connections Discovery
GroupOilRig

OilRig has used netstat -an on a victim to get a listing of network connections.

T1056.001
Keylogging
MalwareHelminth

The executable version of Helminth has a module to log keystrokes.

T1057
Process Discovery
GroupOilRig

OilRig has run tasklist on a victim's machine and used infostealers to capture processes.

T1059.001
PowerShell
MalwareHelminth

One version of Helminth uses a PowerShell script.

T1059.003
Windows Command Shell
MalwareHelminth

Helminth can provide a remote shell. One version of Helminth uses batch scripting.

T1059.005
Visual Basic
MalwareHelminth

One version of Helminth consists of VBScript scripts.

T1069.001
Local Groups
GroupOilRig

OilRig has used net localgroup administrators to find local administrators on compromised systems.

T1069.002
Domain Groups
GroupOilRig

OilRig has used net group /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to find domain group permission settings.

T1071.001
Web Protocols
MalwareHelminth

Helminth can use HTTP for C2.

T1071.004
DNS
MalwareHelminth

Helminth can use DNS for C2.

T1074.001
Local Data Staging
MalwareHelminth

Helminth creates folders to store output from batch scripts prior to sending the information to its C2 server.

T1082
System Information Discovery
GroupOilRig

OilRig has run hostname and systeminfo on a victim.

T1087.001
Local Account
GroupOilRig

OilRig has run net user, net user /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to get account listings on a victim.

T1087.002
Domain Account
GroupOilRig

OilRig has run net user, net user /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to get account listings on a victim.

T1105
Ingress Tool Transfer
MalwareHelminth

Helminth can download additional files.

T1115
Clipboard Data
MalwareHelminth

The executable version of Helminth has a module to log clipboard contents.

T1119
Automated Collection
MalwareHelminth

A Helminth VBScript receives a batch script to execute a set of commands in a command prompt.

T1132.001
Standard Encoding
MalwareHelminth

For C2 over HTTP, Helminth encodes data with base64 and sends it via the "Cookie" field of HTTP requests. For C2 over DNS, Helminth converts ASCII characters into their hexadecimal values and sends the data in cleartext.

T1218.001
Compiled HTML File
GroupOilRig

OilRig has used a CHM payload to load and execute another malicious file once delivered to a victim.

T1547.001
Registry Run Keys / Startup Folder
MalwareHelminth

Helminth establishes persistence by creating a shortcut in the Start Menu folder.

T1547.009
Shortcut Modification
MalwareHelminth

Helminth establishes persistence by creating a shortcut.

T1573.001
Symmetric Cryptography
MalwareHelminth

Helminth encrypts data sent to its C2 server over HTTP with RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.