Mercer, W, et al. (2020, April 16). PoetRAT: Python RAT uses COVID-19 lures to target Azerbaijan public and private sectors. Retrieved April 27, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwarePoetRAT | PoetRAT used voStro.exe, a compiled pypykatz (Python version of Mimikatz), to steal credentials. |
| T1018 Remote System Discovery |
MalwarePoetRAT | PoetRAT used Nmap for remote system discovery. |
| T1027 Obfuscated Files or Information |
MalwarePoetRAT | PoetRAT has used a custom encryption scheme for communication between scripts. |
| T1033 System Owner/User Discovery |
MalwarePoetRAT | PoetRAT sent username, computer name, and the previously generated UUID in reply to a "who" command from C2. |
| T1048 Exfiltration Over Alternative Protocol |
MalwarePoetRAT | PoetRAT has used a .NET tool named dog.exe to exiltrate information over an e-mail account. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwarePoetRAT | |
| T1056.001 Keylogging |
MalwarePoetRAT | PoetRAT has used a Python tool named klog.exe for keylogging. |
| T1057 Process Discovery |
MalwarePoetRAT | PoetRAT has the ability to list all running processes. |
| T1059.005 Visual Basic |
MalwarePoetRAT | PoetRAT has used Word documents with VBScripts to execute malicious activities. |
| T1059.006 Python |
MalwarePoetRAT | PoetRAT was executed with a Python script and worked in conjunction with additional Python-based post-exploitation tools. |
| T1070.004 File Deletion |
MalwarePoetRAT | PoetRAT has the ability to overwrite scripts and delete itself if a sandbox environment is detected. |
| T1082 System Information Discovery |
MalwarePoetRAT | PoetRAT has the ability to gather information about the compromised host. |
| T1083 File and Directory Discovery |
MalwarePoetRAT | PoetRAT has the ability to list files upon receiving the |
| T1105 Ingress Tool Transfer |
MalwarePoetRAT | PoetRAT has the ability to copy files and download/upload files into C2 channels using FTP and HTTPS. |
| T1112 Modify Registry |
MalwarePoetRAT | PoetRAT has made registry modifications to alter its behavior upon execution. |
| T1113 Screen Capture |
MalwarePoetRAT | PoetRAT has the ability to take screen captures. |
| T1119 Automated Collection |
MalwarePoetRAT | PoetRAT used file system monitoring to track modification and enable automatic exfiltration. |
| T1125 Video Capture |
MalwarePoetRAT | PoetRAT has used a Python tool named Bewmac to record the webcam on compromised hosts. |
| T1204.002 Malicious File |
MalwarePoetRAT | PoetRAT has used spearphishing attachments to infect victims. |
| T1497.001 System Checks |
MalwarePoetRAT | PoetRAT checked the size of the hard drive to determine if it was being run in a sandbox environment. In the event of sandbox detection, it would delete itself by overwriting the malware scripts with the contents of "License.txt" and exiting. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePoetRAT | PoetRAT has added a registry key in the <RUN> hive for persistence. |
| T1555.003 Credentials from Web Browsers |
MalwarePoetRAT | PoetRAT has used a Python tool named Browdec.exe to steal browser credentials. |
| T1559.002 Dynamic Data Exchange |
MalwarePoetRAT | PoetRAT was delivered with documents using DDE to execute malicious code. |
| T1560.001 Archive via Utility |
MalwarePoetRAT | PoetRAT has the ability to compress files with zip. |
| T1564.001 Hidden Files and Directories |
MalwarePoetRAT | PoetRAT has the ability to hide and unhide files. |
| T1566.001 Spearphishing Attachment |
MalwarePoetRAT | PoetRAT was distributed via malicious Word documents. |
| T1571 Non-Standard Port |
MalwarePoetRAT | PoetRAT used TLS to encrypt communications over port 143 |
| T1573.002 Asymmetric Cryptography |
MalwarePoetRAT | PoetRAT used TLS to encrypt command and control (C2) communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.