ATT&CKReferencesCybereason Astaroth Feb 2019

Cybereason Astaroth Feb 2019

Salem, E. (2019, February 13). ASTAROTH MALWARE USES LEGITIMATE OS AND ANTIVIRUS PROCESSES TO STEAL PASSWORDS AND PERSONAL DATA. Retrieved April 17, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareAstaroth

Astaroth uses a software packer called Pe123\RPolyCryptor.

T1027.010
Command Obfuscation
MalwareAstaroth

Astaroth has obfuscated and randomized parts of the JScript code it is initiating.

T1041
Exfiltration Over C2 Channel
MalwareAstaroth

Astaroth exfiltrates collected information from its r1.log file to the external C2 server.

T1055.012
Process Hollowing
MalwareAstaroth

Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.

T1057
Process Discovery
MalwareAstaroth

Astaroth searches for different processes on the system.

T1059.003
Windows Command Shell
MalwareAstaroth

Astaroth spawns a CMD process to execute commands.

T1082
System Information Discovery
MalwareAstaroth

Astaroth collects the machine name and keyboard language from the system.

T1105
Ingress Tool Transfer
MalwareAstaroth

Astaroth uses certutil and BITSAdmin to download additional malware.

T1115
Clipboard Data
MalwareAstaroth

Astaroth collects information from the clipboard by using the OpenClipboard() and GetClipboardData() libraries.

T1129
Shared Modules
MalwareAstaroth

Astaroth uses the LoadLibraryExW() function to load additional modules.

T1140
Deobfuscate/Decode Files or Information
MalwareAstaroth

Astaroth uses a fromCharCode() deobfuscation method to avoid explicitly writing execution commands and to hide its code.

T1218.010
Regsvr32
MalwareAstaroth

Astaroth can be loaded through regsvr32.exe.

T1220
XSL Script Processing
MalwareAstaroth

Astaroth executes embedded JScript or VBScript in an XSL stylesheet located on a remote domain.

T1547.009
Shortcut Modification
MalwareAstaroth

Astaroth's initial payload is a malicious .LNK file.

T1552
Unsecured Credentials
MalwareAstaroth

Astaroth uses an external software known as NetPass to recover passwords.

T1555
Credentials from Password Stores
MalwareAstaroth

Astaroth uses an external software known as NetPass to recover passwords.

T1564.003
Hidden Window
MalwareAstaroth

Astaroth loads its module with the XSL script parameter vShow set to zero, which opens the application with a hidden window.

T1568.002
Domain Generation Algorithms
MalwareAstaroth

Astaroth has used a DGA in C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.