POWRUNER

S0184

Malware.View on attack.mitre.org

About this malware

POWRUNER is a PowerShell script that sends and receives commands to and from the C2 server.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1012
Query Registry

POWRUNER may query the Registry by running reg query on a victim.

T1016
System Network Configuration Discovery

POWRUNER may collect network configuration data by running ipconfig /all on a victim.

T1033
System Owner/User Discovery

POWRUNER may collect information about the currently logged in user by running whoami on a victim.

T1047
Windows Management Instrumentation

POWRUNER may use WMI when collecting information about a victim.

T1049
System Network Connections Discovery

POWRUNER may collect active network connections by running netstat -an on a victim.

T1053.005
Scheduled Task

POWRUNER persists through a scheduled task that executes it every minute.

T1057
Process Discovery

POWRUNER may collect process information by running tasklist on a victim.

T1059.001
PowerShell

POWRUNER is written in PowerShell.

T1059.003
Windows Command Shell

POWRUNER can execute commands from its C2 server.

T1069.001
Local Groups

POWRUNER may collect local group information by running net localgroup administrators or a series of other commands on a victim.

T1069.002
Domain Groups

POWRUNER may collect domain group information by running net group /domain or a series of other commands on a victim.

T1071.001
Web Protocols

POWRUNER can use HTTP for C2 communications.

T1071.004
DNS

POWRUNER can use DNS for C2 communications.

T1082
System Information Discovery

POWRUNER may collect information about the system by running hostname and systeminfo on a victim.

T1083
File and Directory Discovery

POWRUNER may enumerate user directories on a victim.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT34 Dec 2017 Open source
    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.