Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1055.001 Dynamic-link Library Injection |
After decrypting itself in memory, RARSTONE downloads a DLL file from its C2 server and loads it in the memory space of a hidden Internet Explorer process. This “downloaded” file is actually not dropped onto the system. |
| T1083 File and Directory Discovery |
RARSTONE obtains installer properties from Uninstall Registry Key entries to obtain information about installed applications and how to uninstall certain applications. |
| T1095 Non-Application Layer Protocol |
RARSTONE uses SSL to encrypt its communication with its C2 server. |
| T1105 Ingress Tool Transfer |
RARSTONE downloads its backdoor component from a C2 server and loads it directly into memory. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.