Kaspersky Lab's Global Research & Analysis Team. (2016, August 9). The ProjectSauron APT. Technical Analysis. Retrieved August 17, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
MalwareRemsec | Remsec can dump the SAM database. |
| T1016 System Network Configuration Discovery |
MalwareRemsec | Remsec can obtain information about network configuration, including the routing table, ARP cache, and DNS cache. |
| T1018 Remote System Discovery |
MalwareRemsec | Remsec can ping or traceroute a remote host. |
| T1025 Data from Removable Media |
MalwareRemsec | Remsec has a package that collects documents from any inserted USB sticks. |
| T1027.013 Encrypted/Encoded File |
MalwareRemsec | Some data in Remsec is encrypted using RC5 in CBC mode, AES-CBC with a hardcoded key, RC4, or Salsa20. Some data is also base64-encoded. |
| T1033 System Owner/User Discovery |
MalwareRemsec | Remsec can obtain information about the current user. |
| T1046 Network Service Discovery |
MalwareRemsec | Remsec has a plugin that can perform ARP scanning as well as port scanning. |
| T1049 System Network Connections Discovery |
MalwareRemsec | Remsec can obtain a list of active connections and open ports. |
| T1053.005 Scheduled Task |
MalwareRemsec | Remsec schedules the execution one of its modules by creating a new scheduler task. |
| T1055.001 Dynamic-link Library Injection |
MalwareRemsec | Remsec can perform DLL injection. |
| T1056.001 Keylogging |
MalwareRemsec | Remsec contains a keylogger component. |
| T1057 Process Discovery |
MalwareRemsec | Remsec can obtain a process list from the victim. |
| T1068 Exploitation for Privilege Escalation |
MalwareRemsec | Remsec has a plugin to drop and execute vulnerable Outpost Sandbox or avast! Virtualization drivers in order to gain kernel mode privileges. |
| T1070.004 File Deletion |
MalwareRemsec | Remsec is capable of deleting files on the victim. It also securely removes itself after collecting and exfiltrating data. |
| T1071.001 Web Protocols |
MalwareRemsec | Remsec is capable of using HTTP and HTTPS for C2. |
| T1071.003 Mail Protocols |
MalwareRemsec | Remsec is capable of using SMTP for C2. |
| T1071.004 DNS |
MalwareRemsec | Remsec is capable of using DNS for C2. |
| T1082 System Information Discovery |
MalwareRemsec | Remsec can obtain the OS version information, computer name, processor architecture, machine role, and OS edition. |
| T1083 File and Directory Discovery |
MalwareRemsec | Remsec is capable of listing contents of folders on the victim. Remsec also searches for custom network encryption software on victims. |
| T1087.001 Local Account |
MalwareRemsec | Remsec can obtain a list of users. |
| T1105 Ingress Tool Transfer |
MalwareRemsec | Remsec contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS. |
| T1518.001 Security Software Discovery |
MalwareRemsec | Remsec has a plugin detect security products via active drivers. |
| T1652 Device Driver Discovery |
MalwareRemsec | Remsec has a plugin to detect active drivers of some security products. |
| T1686.003 Windows Host Firewall |
MalwareRemsec | Remsec can add or remove applications or ports on the Windows firewall or disable it entirely. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.