ATT&CKReferencesCrowdstrike DNC June 2016

Crowdstrike DNC June 2016

Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups2

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareCHOPSTICK

CHOPSTICK is capable of performing keylogging.

T1059
Command and Scripting Interpreter
MalwareCHOPSTICK

CHOPSTICK is capable of performing remote command execution.

T1059.003
Windows Command Shell
MalwareXTunnel

XTunnel has been used to execute remote commands.

T1070.006
Timestomp
GroupAPT28

APT28 has performed timestomping on victim files.

T1090
Proxy
MalwareXTunnel

XTunnel relays traffic between a C2 server and a victim.

T1105
Ingress Tool Transfer
MalwareCHOPSTICK

CHOPSTICK is capable of performing remote file transmission.

T1218.011
Rundll32
GroupAPT28

APT28 executed CHOPSTICK by using rundll32 commands such as rundll32.exe “C:\Windows\twain_64.dll”. APT28 also executed a .dll for a first stage dropper using rundll32.exe. An APT28 loader Trojan saved a batch script that uses rundll32 to execute a DLL payload.

T1685.005
Clear Windows Event Logs
GroupAPT28

APT28 has cleared event logs, including by using the commands wevtutil cl System and wevtutil cl Security.

T1685.005
Clear Windows Event Logs
ToolWevtutil

Wevtutil can be used to clear system and security event logs from the system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.