ATT&CKReferencesAnomali Rocke March 2019

Anomali Rocke March 2019

Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.

Open the source

Techniques2

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1014
Rootkit
GroupRocke

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.

T1021.004
SSH
GroupRocke

Rocke has spread its coinminer via SSH.

T1027
Obfuscated Files or Information
GroupRocke

Rocke has modified UPX headers after packing files to break unpackers.

T1027.002
Software Packing
GroupRocke

Rocke's miner has created UPX-packed files in the Windows Start Menu Folder.

T1027.004
Compile After Delivery
GroupRocke

Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC).

T1037
Boot or Logon Initialization Scripts
GroupRocke

Rocke has installed an "init.d" startup script to maintain persistence.

T1046
Network Service Discovery
GroupRocke

Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers.

T1053.003
Cron
GroupRocke

Rocke installed a cron job that downloaded and executed files from the C2.

T1057
Process Discovery
GroupRocke

Rocke can detect a running process's PID on the infected machine.

T1059.006
Python
GroupRocke

Rocke has used Python-based malware to install and spread their coinminer.

T1070.004
File Deletion
GroupRocke

Rocke has deleted files on infected machines.

T1070.006
Timestomp
GroupRocke

Rocke has changed the time stamp of certain files.

T1071.001
Web Protocols
GroupRocke

Rocke has executed wget and curl commands to Pastebin over the HTTPS protocol.

T1082
System Information Discovery
GroupRocke

Rocke has used uname -m to collect the name and information about the infected system's kernel.

T1102
Web Service
GroupRocke

Rocke has used Pastebin, Gitee, and GitLab for Command and Control.

T1102.001
Dead Drop Resolver
GroupRocke

Rocke has used Pastebin to check the version of beaconing malware and redirect to another Pastebin hosting updated malware.

T1222.002
Linux and Mac Permissions
GroupRocke

Rocke has changed file permissions of files so they could not be modified.

T1543.002
Systemd Service
GroupRocke

Rocke has installed a systemd service script to maintain persistence.

T1552.004
Private Keys
GroupRocke

Rocke has used SSH private keys on the infected machine to spread its coinminer throughout a network.

T1571
Non-Standard Port
GroupRocke

Rocke's miner connects to a C2 server using port 51640.

T1574.006
Dynamic Linker Hijacking
GroupRocke

Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists.

T1685.006
Clear Linux or Mac System Logs
GroupRocke

Rocke has cleared log files within the /var/log/ folder.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.