3PARA RAT

S0066

Malware.View on attack.mitre.org

About this malware

3PARA RAT is a remote access tool (RAT) programmed in C++ that has been used by Putter Panda.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1070.006
Timestomp

3PARA RAT has a command to set certain attributes such as creation/modification timestamps on files.

T1071.001
Web Protocols

3PARA RAT uses HTTP for command and control.

T1083
File and Directory Discovery

3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory.

T1573.001
Symmetric Cryptography

3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode with a key derived from the MD5 hash of the string HYF54&%9&jkMCXuiS. 3PARA RAT will use an 8-byte XOR key derived from the string HYF54&%9&jkMCXuiS if the DES decoding fails

Groups that use it1

Campaigns0

None recorded.

References1

  1. CrowdStrike Putter Panda Open source
    Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.