ATT&CKReferencesESET Carbon Mar 2017

ESET Carbon Mar 2017

ESET. (2017, March 30). Carbon Paper: Peering into Turla’s second stage backdoor. Retrieved November 7, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareCarbon

Carbon enumerates values in the Registry.

T1016
System Network Configuration Discovery
MalwareCarbon

Carbon can collect the IP address of the victims and other computers on the network using the commands: ipconfig -all nbtstat -n, and nbtstat -s.

T1027
Obfuscated Files or Information
MalwareCarbon

Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
MalwareCarbon

Carbon uses HTTP to send data to the C2 server.

T1053.005
Scheduled Task
MalwareCarbon

Carbon creates several tasks for later execution to continue persistence on the victim’s machine.

T1055.001
Dynamic-link Library Injection
MalwareCarbon

Carbon has a command to inject code into a process.

T1057
Process Discovery
MalwareCarbon

Carbon can list the processes on the victim’s machine.

T1074.001
Local Data Staging
MalwareCarbon

Carbon creates a base directory that contains the files and folders that are collected.

T1095
Non-Application Layer Protocol
MalwareCarbon

Carbon uses TCP and UDP for C2.

T1140
Deobfuscate/Decode Files or Information
MalwareCarbon

Carbon decrypts task and configuration files for execution.

T1543.003
Windows Service
MalwareCarbon

Carbon establishes persistence by creating a service and naming it based off the operating system version running on the current machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.