SHOTPUT

S0063

Malware.View on attack.mitre.org

About this malware

SHOTPUT is a custom backdoor used by APT3.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1018
Remote System Discovery

SHOTPUT has a command to list all servers in the domain, as well as one to locate domain controllers on a domain.

T1027
Obfuscated Files or Information

SHOTPUT is obscured using XOR encoding and appended to a valid GIF file.

T1049
System Network Connections Discovery

SHOTPUT uses netstat to list TCP connection status.

T1057
Process Discovery

SHOTPUT has a command to obtain a process listing.

T1083
File and Directory Discovery

SHOTPUT has a command to obtain a directory listing.

T1087.001
Local Account

SHOTPUT has a command to retrieve information about connected users.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye Clandestine Wolf Open source
    Eng, E., Caselden, D.. (2015, June 23). Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaign. Retrieved January 14, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.