Malware.View on attack.mitre.org
ServHelper is a backdoor first observed in late 2018. The backdoor is written in Delphi and is typically delivered as a DLL file.
| Technique | Procedure example |
|---|---|
| T1021.001 Remote Desktop Protocol |
ServHelper has commands for adding a remote desktop user and sending RDP traffic to the attacker through a reverse SSH tunnel. |
| T1033 System Owner/User Discovery |
ServHelper will attempt to enumerate the username of the victim. |
| T1036.010 Masquerade Account Name |
ServHelper has created a new user named `supportaccount`. |
| T1053.005 Scheduled Task |
ServHelper contains modules that will use schtasks to carry out malicious operations. |
| T1059.001 PowerShell |
ServHelper has the ability to execute a PowerShell script to get information from the infected host. |
| T1059.003 Windows Command Shell |
ServHelper can execute shell commands against cmd. |
| T1070.004 File Deletion |
ServHelper has a module to delete itself from the infected machine. |
| T1071.001 Web Protocols |
ServHelper uses HTTP for C2. |
| T1082 System Information Discovery |
ServHelper will attempt to enumerate Windows version and system architecture. |
| T1098.007 Additional Local or Domain Groups |
ServHelper has added a user named "supportaccount" to the Remote Desktop Users and Administrators groups. |
| T1105 Ingress Tool Transfer |
ServHelper may download additional files to execute. |
| T1136.001 Local Account |
ServHelper has created a new user named "supportaccount". |
| T1218.011 Rundll32 |
ServHelper contains a module for downloading and executing DLLs that leverages |
| T1547.001 Registry Run Keys / Startup Folder |
ServHelper may attempt to establish persistence via the |
| T1573.002 Asymmetric Cryptography |
ServHelper may set up a reverse SSH tunnel to give the attacker access to services running on the victim, such as RDP. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.