Doaty, J., Garrett, P.. (2018, September 10). We’re Seeing a Resurgence of the Demonic Astaroth WMIC Trojan. Retrieved September 25, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareAstaroth | Astaroth collects the external IP address from the system. |
| T1047 Windows Management Instrumentation |
MalwareAstaroth | Astaroth uses WMIC to execute payloads. |
| T1056.001 Keylogging |
MalwareAstaroth | Astaroth logs keystrokes from the victim's machine. |
| T1059.007 JavaScript |
MalwareAstaroth | Astaroth uses JavaScript to perform its core functionalities. |
| T1074.001 Local Data Staging |
MalwareAstaroth | Astaroth collects data in a plaintext file named r1.log before exfiltration. |
| T1082 System Information Discovery |
MalwareAstaroth | Astaroth collects the machine name and keyboard language from the system. |
| T1105 Ingress Tool Transfer |
MalwareAstaroth | Astaroth uses certutil and BITSAdmin to download additional malware. |
| T1124 System Time Discovery |
MalwareAstaroth | Astaroth collects the timestamp from the infected machine. |
| T1132.001 Standard Encoding |
MalwareAstaroth | Astaroth encodes data using Base64 before sending it to the C2 server. |
| T1218.001 Compiled HTML File |
MalwareAstaroth | Astaroth uses ActiveX objects for file execution and manipulation. |
| T1518.001 Security Software Discovery |
MalwareAstaroth | Astaroth checks for the presence of Avast antivirus in the |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAstaroth | Astaroth creates a startup item for persistence. |
| T1547.009 Shortcut Modification |
MalwareAstaroth | Astaroth's initial payload is a malicious .LNK file. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.