ClearSky Cyber Security. (2021, January). “Lebanese Cedar” APT Global Lebanese Espionage Campaign Leveraging Web Servers. Retrieved February 10, 2021.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to collect information from the local database. |
| T1007 System Service Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can obtain a list of the services from a system. |
| T1014 Rootkit |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to use a rootkit on a system. |
| T1016 System Network Configuration Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can gather the IP address from the victim's machine using the IP config command. |
| T1033 System Owner/User Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can obtain a list of user accounts from a victim's machine. |
| T1041 Exfiltration Over C2 Channel |
MalwareCaterpillar WebShell | Caterpillar WebShell can upload files over the C2 channel. |
| T1046 Network Service Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to use a port scanner on a system. |
| T1056.001 Keylogging |
MalwareExplosive | Explosive has leveraged its keylogging capabilities to gain access to administrator accounts on target servers. |
| T1057 Process Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can gather a list of processes running on the machine. |
| T1059.003 Windows Command Shell |
MalwareCaterpillar WebShell | Caterpillar WebShell can run commands on the compromised asset with CMD functions. |
| T1069.001 Local Groups |
MalwareCaterpillar WebShell | Caterpillar WebShell can obtain a list of local groups of users from a system. |
| T1082 System Information Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to gather information from the compromised asset, including the computer version, computer name, IIS version, and more. |
| T1083 File and Directory Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can search for files in directories. |
| T1105 Ingress Tool Transfer |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to download and upload files to the system. |
| T1105 Ingress Tool Transfer |
GroupVolatile Cedar | Volatile Cedar can deploy additional tools. |
| T1110 Brute Force |
MalwareCaterpillar WebShell | Caterpillar WebShell has a module to perform brute force attacks on a system. |
| T1112 Modify Registry |
MalwareCaterpillar WebShell | Caterpillar WebShell has a command to modify a Registry key. |
| T1190 Exploit Public-Facing Application |
GroupVolatile Cedar | Volatile Cedar has targeted publicly facing web servers, with both automatic and manual vulnerability discovery. |
| T1505.003 Web Shell |
GroupVolatile Cedar | Volatile Cedar can inject web shell code into a server. |
| T1573.001 Symmetric Cryptography |
MalwareExplosive | Explosive has encrypted communications with the RC4 method. |
| T1595.002 Vulnerability Scanning |
GroupVolatile Cedar | Volatile Cedar has performed vulnerability scans of the target server. |
| T1595.003 Wordlist Scanning |
GroupVolatile Cedar | Volatile Cedar has used DirBuster and GoBuster to brute force web directories and DNS subdomains. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.