ATT&CKReferencesFireEye APT34 Dec 2017

FireEye APT34 Dec 2017

Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples30

TechniqueUsed byProcedure example
T1012
Query Registry
MalwarePOWRUNER

POWRUNER may query the Registry by running reg query on a victim.

T1016
System Network Configuration Discovery
MalwarePOWRUNER

POWRUNER may collect network configuration data by running ipconfig /all on a victim.

T1027.013
Encrypted/Encoded File
GroupOilRig

OilRig has encrypted and encoded data in its malware, including by using base64.

T1033
System Owner/User Discovery
MalwarePOWRUNER

POWRUNER may collect information about the currently logged in user by running whoami on a victim.

T1047
Windows Management Instrumentation
MalwarePOWRUNER

POWRUNER may use WMI when collecting information about a victim.

T1049
System Network Connections Discovery
MalwarePOWRUNER

POWRUNER may collect active network connections by running netstat -an on a victim.

T1053.005
Scheduled Task
MalwarePOWRUNER

POWRUNER persists through a scheduled task that executes it every minute.

T1057
Process Discovery
MalwarePOWRUNER

POWRUNER may collect process information by running tasklist on a victim.

T1059
Command and Scripting Interpreter
GroupOilRig

OilRig has used various types of scripting for execution.

T1059.001
PowerShell
MalwareBONDUPDATER

BONDUPDATER is written in PowerShell.

T1059.001
PowerShell
GroupOilRig

OilRig has used PowerShell scripts for execution, including use of a macro to run a PowerShell command to decode file contents.

T1059.001
PowerShell
MalwarePOWRUNER

POWRUNER is written in PowerShell.

T1059.003
Windows Command Shell
GroupOilRig

OilRig has used macros to deliver malware such as QUADAGENT and OopsIE. OilRig has used batch scripts.

T1059.003
Windows Command Shell
MalwarePOWRUNER

POWRUNER can execute commands from its C2 server.

T1069.001
Local Groups
MalwarePOWRUNER

POWRUNER may collect local group information by running net localgroup administrators or a series of other commands on a victim.

T1069.002
Domain Groups
MalwarePOWRUNER

POWRUNER may collect domain group information by running net group /domain or a series of other commands on a victim.

T1070.004
File Deletion
GroupOilRig

OilRig has deleted files associated with their payload after execution.

T1071.001
Web Protocols
MalwarePOWRUNER

POWRUNER can use HTTP for C2 communications.

T1071.004
DNS
MalwarePOWRUNER

POWRUNER can use DNS for C2 communications.

T1082
System Information Discovery
MalwarePOWRUNER

POWRUNER may collect information about the system by running hostname and systeminfo on a victim.

T1083
File and Directory Discovery
MalwarePOWRUNER

POWRUNER may enumerate user directories on a victim.

T1087.002
Domain Account
MalwarePOWRUNER

POWRUNER may collect user account information by running net user /domain or a series of other commands on a victim.

T1105
Ingress Tool Transfer
MalwarePOWRUNER

POWRUNER can download or upload files from its C2 server.

T1105
Ingress Tool Transfer
GroupOilRig

OilRig had downloaded remote files onto victim infrastructure.

T1113
Screen Capture
MalwarePOWRUNER

POWRUNER can capture a screenshot from a victim.

T1132.001
Standard Encoding
MalwarePOWRUNER

POWRUNER can use base64 encoded C2 communications.

T1140
Deobfuscate/Decode Files or Information
GroupOilRig

A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims.

T1518.001
Security Software Discovery
MalwarePOWRUNER

POWRUNER may collect information on the victim's anti-virus software.

T1564.003
Hidden Window
MalwareBONDUPDATER

BONDUPDATER uses -windowstyle hidden to conceal a PowerShell window that downloads a payload.

T1568.002
Domain Generation Algorithms
MalwareBONDUPDATER

BONDUPDATER uses a DGA to communicate with command and control servers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.