WINERACK

S0219

Malware.View on attack.mitre.org

About this malware

WINERACK is a backdoor used by APT37.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1007
System Service Discovery

WINERACK can enumerate services.

T1010
Application Window Discovery

WINERACK can enumerate active windows.

T1033
System Owner/User Discovery

WINERACK can gather information on the victim username.

T1057
Process Discovery

WINERACK can enumerate processes.

T1059
Command and Scripting Interpreter

WINERACK can create a reverse shell that utilizes statically-linked Wine cmd.exe code to emulate Windows command prompt commands.

T1082
System Information Discovery

WINERACK can gather information about the host.

T1083
File and Directory Discovery

WINERACK can enumerate files and directories.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT37 Feb 2018 Open source
    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.