Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
GroupPutter Panda | Droppers used by Putter Panda use RC4 or a 16-byte XOR key consisting of the bytes 0xA0 – 0xAF to obfuscate payloads. |
| T1055.001 Dynamic-link Library Injection |
GroupPutter Panda | An executable dropped onto victims by Putter Panda aims to inject the specified DLL into a process that would normally be accessing the network, including Outlook Express (msinm.exe), Outlook (outlook.exe), Internet Explorer (iexplore.exe), and Firefox (firefox.exe). |
| T1057 Process Discovery |
Malware4H RAT | 4H RAT has the capability to obtain a listing of running processes (including loaded modules). |
| T1059.003 Windows Command Shell |
Malware4H RAT | 4H RAT has the capability to create a remote shell. |
| T1059.003 Windows Command Shell |
Malwarehttpclient | httpclient opens cmd.exe on the victim. |
| T1070.004 File Deletion |
Malwarepngdowner | pngdowner deletes content from C2 communications that was saved to the user's temporary directory. |
| T1070.006 Timestomp |
Malware3PARA RAT | 3PARA RAT has a command to set certain attributes such as creation/modification timestamps on files. |
| T1071.001 Web Protocols |
Malware3PARA RAT | 3PARA RAT uses HTTP for command and control. |
| T1071.001 Web Protocols |
Malware4H RAT | 4H RAT uses HTTP for command and control. |
| T1071.001 Web Protocols |
Malwarepngdowner | pngdowner uses HTTP for command and control. |
| T1071.001 Web Protocols |
Malwarehttpclient | httpclient uses HTTP for command and control. |
| T1082 System Information Discovery |
Malware4H RAT | 4H RAT sends an OS version identifier in its beacons. |
| T1083 File and Directory Discovery |
Malware3PARA RAT | 3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory. |
| T1083 File and Directory Discovery |
Malware4H RAT | 4H RAT has the capability to obtain file and directory listings. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupPutter Panda | A dropper used by Putter Panda installs itself into the ASEP Registry key |
| T1552.001 Credentials In Files |
Malwarepngdowner | If an initial connectivity check fails, pngdowner attempts to extract proxy details and credentials from Windows Protected Storage and from the IE Credentials Store. This allows the adversary to use the proxy credentials for subsequent requests if they enable outbound HTTP access. |
| T1573.001 Symmetric Cryptography |
Malwarehttpclient | httpclient encrypts C2 content with XOR using a single byte, 0x12. |
| T1573.001 Symmetric Cryptography |
Malware4H RAT | 4H RAT obfuscates C2 communication using a 1-byte XOR with the key 0xBE. |
| T1573.001 Symmetric Cryptography |
Malware3PARA RAT | 3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode with a key derived from the MD5 hash of the string HYF54&%9&jkMCXuiS. 3PARA RAT will use an 8-byte XOR key derived from the string HYF54&%9&jkMCXuiS if the DES decoding fails |
| T1685 Disable or Modify Tools |
GroupPutter Panda | Malware used by Putter Panda attempts to terminate processes corresponding to two components of Sophos Anti-Virus (SAVAdminService.exe and SavService.exe). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.