Salem, E. (2019, February 13). ASTAROTH MALWARE USES LEGITIMATE OS AND ANTIVIRUS PROCESSES TO STEAL PASSWORDS AND PERSONAL DATA. Retrieved April 17, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareAstaroth | Astaroth uses a software packer called Pe123\RPolyCryptor. |
| T1027.010 Command Obfuscation |
MalwareAstaroth | Astaroth has obfuscated and randomized parts of the JScript code it is initiating. |
| T1041 Exfiltration Over C2 Channel |
MalwareAstaroth | Astaroth exfiltrates collected information from its r1.log file to the external C2 server. |
| T1055.012 Process Hollowing |
MalwareAstaroth | Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code. |
| T1057 Process Discovery |
MalwareAstaroth | Astaroth searches for different processes on the system. |
| T1059.003 Windows Command Shell |
MalwareAstaroth | Astaroth spawns a CMD process to execute commands. |
| T1082 System Information Discovery |
MalwareAstaroth | Astaroth collects the machine name and keyboard language from the system. |
| T1105 Ingress Tool Transfer |
MalwareAstaroth | Astaroth uses certutil and BITSAdmin to download additional malware. |
| T1115 Clipboard Data |
MalwareAstaroth | Astaroth collects information from the clipboard by using the OpenClipboard() and GetClipboardData() libraries. |
| T1129 Shared Modules |
MalwareAstaroth | Astaroth uses the LoadLibraryExW() function to load additional modules. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAstaroth | Astaroth uses a fromCharCode() deobfuscation method to avoid explicitly writing execution commands and to hide its code. |
| T1218.010 Regsvr32 |
MalwareAstaroth | Astaroth can be loaded through regsvr32.exe. |
| T1220 XSL Script Processing |
MalwareAstaroth | Astaroth executes embedded JScript or VBScript in an XSL stylesheet located on a remote domain. |
| T1547.009 Shortcut Modification |
MalwareAstaroth | Astaroth's initial payload is a malicious .LNK file. |
| T1552 Unsecured Credentials |
MalwareAstaroth | Astaroth uses an external software known as NetPass to recover passwords. |
| T1555 Credentials from Password Stores |
MalwareAstaroth | Astaroth uses an external software known as NetPass to recover passwords. |
| T1564.003 Hidden Window |
MalwareAstaroth | Astaroth loads its module with the XSL script parameter |
| T1568.002 Domain Generation Algorithms |
MalwareAstaroth | Astaroth has used a DGA in C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.