ATT&CKReferencesFlashpoint FIN 7 March 2019

Flashpoint FIN 7 March 2019

Platt, J. and Reeves, J.. (2019, March). FIN7 Revisited: Inside Astra Panel and SQLRat Malware. Retrieved June 18, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareSQLRat

SQLRat has used a character insertion obfuscation technique, making the script appear to contain Chinese characters.

T1053.005
Scheduled Task
MalwareSQLRat

SQLRat has created scheduled tasks in %appdata%\Roaming\Microsoft\Templates\.

T1053.005
Scheduled Task
GroupFIN7

FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence.

T1059
Command and Scripting Interpreter
GroupFIN7

FIN7 used SQL scripts to help perform tasks on the victim's machine.

T1059.001
PowerShell
MalwareSQLRat

SQLRat has used PowerShell to create a Meterpreter session.

T1059.003
Windows Command Shell
MalwareSQLRat

SQLRat has used SQL to execute JavaScript and VB scripts on the host system.

T1059.003
Windows Command Shell
GroupFIN7

FIN7 used the command prompt to launch commands on the victim’s machine. Additionally, FIN7 has used cmd.exe to open the Run dialog by sending the “Windows + R” keys through malicious USBs acting as virtual keyboards.

T1059.005
Visual Basic
GroupFIN7

FIN7 used VBS scripts to help perform tasks on the victim's machine.

T1059.007
JavaScript
GroupFIN7

FIN7 used JavaScript scripts to help perform tasks on the victim's machine.

T1070.004
File Deletion
MalwareSQLRat

SQLRat has used been observed deleting scripts once used.

T1105
Ingress Tool Transfer
MalwareSQLRat

SQLRat can make a direct SQL connection to a Microsoft database controlled by the attackers, retrieve an item from the bindata table, then write and execute the file on disk.

T1140
Deobfuscate/Decode Files or Information
MalwareSQLRat

SQLRat has scripts that are responsible for deobfuscating additional scripts.

T1204.002
Malicious File
MalwareSQLRat

SQLRat relies on users clicking on an embedded image to execute the scripts.

T1566.001
Spearphishing Attachment
GroupFIN7

FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.