Misdat

S0083

Malware.View on attack.mitre.org

About this malware

Misdat is a backdoor that was used in Operation Dust Storm from 2010 to 2011.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1005
Data from Local System

Misdat has collected files and data from a compromised host.

T1027.002
Software Packing

Misdat was typically packed using UPX.

T1036.005
Match Legitimate Resource Name or Location

Misdat saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1041
Exfiltration Over C2 Channel

Misdat has uploaded files and data to its C2 servers.

T1059.003
Windows Command Shell

Misdat is capable of providing shell functionality to the attacker to execute commands.

T1070.004
File Deletion

Misdat is capable of deleting the backdoor file.

T1070.006
Timestomp

Many Misdat samples were programmed using Borland Delphi, which will mangle the default PE compile timestamp of a file.

T1070.009
Clear Persistence

Misdat is capable of deleting Registry keys used for persistence.

T1082
System Information Discovery

The initial beacon packet for Misdat contains the operating system version of the victim.

T1083
File and Directory Discovery

Misdat is capable of running commands to obtain a list of files and directories, as well as enumerating logical drives.

T1095
Non-Application Layer Protocol

Misdat network traffic communicates over a raw socket.

T1105
Ingress Tool Transfer

Misdat is capable of downloading files from the C2.

T1106
Native API

Misdat has used Windows APIs, including `ExitWindowsEx` and `GetKeyboardType`.

T1132.001
Standard Encoding

Misdat network traffic is Base64-encoded plaintext.

T1547
Boot or Logon Autostart Execution

Misdat has created registry keys for persistence, including `HKCU\Software\dnimtsoleht\StubPath`, `HKCU\Software\snimtsOleht\StubPath`, `HKCU\Software\Backtsaleht\StubPath`, `HKLM\SOFTWARE\Microsoft\Active Setup\Installed. Components\{3bf41072-b2b1-21c8-b5c1-bd56d32fbda7}`, and `HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{3ef41072-a2f1-21c8-c5c1-70c2c3bc7905}`.

View all 16 procedure examples

Groups that use it0

None recorded.

Campaigns1

References1

  1. Cylance Dust Storm Open source
    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.