Malware.View on attack.mitre.org
OwaAuth is a Web shell and credential stealer deployed to Microsoft Exchange servers that appears to be exclusively used by Threat Group-3390.
| Technique | Procedure example |
|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
OwaAuth uses the filename owaauth.dll, which is a legitimate file that normally resides in |
| T1056.001 Keylogging |
OwaAuth captures and DES-encrypts credentials before writing the username and password to a log file, |
| T1070.006 Timestomp |
OwaAuth has a command to timestop a file or directory. |
| T1071.001 Web Protocols |
OwaAuth uses incoming HTTP requests with a username keyword and commands and handles them as instructions to perform actions. |
| T1083 File and Directory Discovery |
OwaAuth has a command to list its directory and logical drives. |
| T1505.003 Web Shell |
OwaAuth is a Web shell that appears to be exclusively used by Threat Group-3390. It is installed as an ISAPI filter on Exchange servers and shares characteristics with the China Chopper Web shell. |
| T1505.004 IIS Components |
OwaAuth has been loaded onto Exchange servers and disguised as an ISAPI filter (owaauth.dll). The IIS w3wp.exe process then loads the malicious DLL. |
| T1560.003 Archive via Custom Method |
OwaAuth DES-encrypts captured credentials using the key 12345678 before writing the credentials to a log file. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.