ASERT Team. (2018, April 04). Innaput Actors Utilize Remote Access Trojan Since 2016, Presumably Targeting Victim Files. Retrieved July 9, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareInnaputRAT | InnaputRAT uses an 8-byte XOR key to obfuscate API names and other strings contained in the payload. |
| T1036.004 Masquerade Task or Service |
MalwareInnaputRAT | InnaputRAT variants have attempted to appear legitimate by adding a new service named OfficeUpdateService. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareInnaputRAT | InnaputRAT variants have attempted to appear legitimate by using the file names SafeApp.exe and NeutralApp.exe. |
| T1059.003 Windows Command Shell |
MalwareInnaputRAT | InnaputRAT launches a shell to execute commands on the victim’s machine. |
| T1070.004 File Deletion |
MalwareInnaputRAT | InnaputRAT has a command to delete files. |
| T1082 System Information Discovery |
MalwareInnaputRAT | InnaputRAT gathers system information. |
| T1083 File and Directory Discovery |
MalwareInnaputRAT | InnaputRAT enumerates directories and obtains file attributes on a system. |
| T1106 Native API |
MalwareInnaputRAT | InnaputRAT uses the API call ShellExecuteW for execution. |
| T1543.003 Windows Service |
MalwareInnaputRAT | Some InnaputRAT variants create a new Windows service to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareInnaputRAT | Some InnaputRAT variants establish persistence by modifying the Registry key |
| T1680 Local Storage Discovery |
MalwareInnaputRAT | InnaputRAT gathers volume drive information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.