ATT&CKReferencesASERT InnaputRAT April 2018

ASERT InnaputRAT April 2018

ASERT Team. (2018, April 04). Innaput Actors Utilize Remote Access Trojan Since 2016, Presumably Targeting Victim Files. Retrieved July 9, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareInnaputRAT

InnaputRAT uses an 8-byte XOR key to obfuscate API names and other strings contained in the payload.

T1036.004
Masquerade Task or Service
MalwareInnaputRAT

InnaputRAT variants have attempted to appear legitimate by adding a new service named OfficeUpdateService.

T1036.005
Match Legitimate Resource Name or Location
MalwareInnaputRAT

InnaputRAT variants have attempted to appear legitimate by using the file names SafeApp.exe and NeutralApp.exe.

T1059.003
Windows Command Shell
MalwareInnaputRAT

InnaputRAT launches a shell to execute commands on the victim’s machine.

T1070.004
File Deletion
MalwareInnaputRAT

InnaputRAT has a command to delete files.

T1082
System Information Discovery
MalwareInnaputRAT

InnaputRAT gathers system information.

T1083
File and Directory Discovery
MalwareInnaputRAT

InnaputRAT enumerates directories and obtains file attributes on a system.

T1106
Native API
MalwareInnaputRAT

InnaputRAT uses the API call ShellExecuteW for execution.

T1543.003
Windows Service
MalwareInnaputRAT

Some InnaputRAT variants create a new Windows service to establish persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareInnaputRAT

Some InnaputRAT variants establish persistence by modifying the Registry key HKU\<SID>\Software\Microsoft\Windows\CurrentVersion\Run:%appdata%\NeutralApp\NeutralApp.exe.

T1680
Local Storage Discovery
MalwareInnaputRAT

InnaputRAT gathers volume drive information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.