ATT&CKReferencesUnit 42 Playbook Dec 2017

Unit 42 Playbook Dec 2017

Unit 42. (2017, December 15). Unit 42 Playbook Viewer. Retrieved December 20, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareJHUHUGIT

A JHUHUGIT variant gathers network interface card information.

T1037.001
Logon Script (Windows)
GroupAPT28

An APT28 loader Trojan adds the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

T1057
Process Discovery
GroupAPT28

An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions.

T1057
Process Discovery
MalwareHelminth

Helminth has used Tasklist to get information on processes.

T1059.001
PowerShell
GroupDarkHydrus

DarkHydrus leveraged PowerShell to download and execute additional scripts for execution.

T1059.003
Windows Command Shell
GroupAPT28

An APT28 loader Trojan uses a cmd.exe and batch script to run its payload. The group has also used macros to execute payloads.

T1069.001
Local Groups
MalwareHelminth

Helminth has checked the local administrators group.

T1069.002
Domain Groups
MalwareHelminth

Helminth has checked for the domain admin group and Exchange Trusted Subsystem groups using the commands net group Exchange Trusted Subsystem /domain and net group domain admins /domain.

T1071.001
Web Protocols
MalwareJHUHUGIT

JHUHUGIT variants have communicated with C2 servers over HTTP and HTTPS.

T1105
Ingress Tool Transfer
GroupAPT28

APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant.

T1113
Screen Capture
MalwareJHUHUGIT

A JHUHUGIT variant takes screenshots by simulating the user pressing the "Take Screenshot" key (VK_SCREENSHOT), accessing the screenshot saved in the clipboard, and converting it to a JPG image.

T1115
Clipboard Data
MalwareJHUHUGIT

A JHUHUGIT variant accesses a screenshot saved in the clipboard and converts it to a JPG image.

T1132.001
Standard Encoding
MalwareJHUHUGIT

A JHUHUGIT variant encodes C2 POST data base64.

T1204.002
Malicious File
GroupDarkHydrus

DarkHydrus has sent malware that required users to hit the enable button in Microsoft Excel to allow an .iqy file to be downloaded.

T1218.011
Rundll32
GroupAPT28

APT28 executed CHOPSTICK by using rundll32 commands such as rundll32.exe “C:\Windows\twain_64.dll”. APT28 also executed a .dll for a first stage dropper using rundll32.exe. An APT28 loader Trojan saved a batch script that uses rundll32 to execute a DLL payload.

T1566.001
Spearphishing Attachment
GroupDarkHydrus

DarkHydrus has sent spearphishing emails with password-protected RAR archives containing malicious Excel Web Query files (.iqy). The group has also sent spearphishing emails that contained malicious Microsoft Office documents that use the “attachedTemplate” technique to load a template from a remote server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.