ATT&CKReferencesESET ComRAT May 2020

ESET ComRAT May 2020

Faou, M. (2020, May). From Agent.btz to ComRAT v4: A ten-year journey. Retrieved June 15, 2020.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples37

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareComRAT

ComRAT can check the default browser by querying HKCR\http\shell\open\command.

T1016
System Network Configuration Discovery
GroupTurla

Turla surveys a system upon check-in to discover network configuration details using the arp -a, nbtstat -n, net config, ipconfig /all, and route commands, as well as NBTscan. Turla RPC backdoors have also retrieved registered RPC interface information from process memory.

T1016.001
Internet Connection Discovery
GroupTurla

Turla has used tracert to check internet connectivity.

T1018
Remote System Discovery
GroupTurla

Turla surveys a system upon check-in to discover remote systems on a local network using the net view and net view /DOMAIN commands. Turla has also used net group "Domain Computers" /domain, net group "Domain Controllers" /domain, and net group "Exchange Servers" /domain to enumerate domain computers, including the organization's DC and Exchange Server.

T1027
Obfuscated Files or Information
MalwareComRAT

ComRAT has encrypted its virtual file system using AES-256 in XTS mode.

T1027.009
Embedded Payloads
MalwareComRAT

ComRAT has embedded a XOR encrypted communications module inside the orchestrator module.

T1027.010
Command Obfuscation
MalwareComRAT

ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts.

T1027.011
Fileless Storage
MalwareComRAT

ComRAT has stored encrypted orchestrator code and payloads in the Registry.

T1029
Scheduled Transfer
MalwareComRAT

ComRAT has been programmed to sleep outside local business hours (9 to 5, Monday to Friday).

T1036.004
Masquerade Task or Service
MalwareComRAT

ComRAT has used a task name associated with Windows SQM Consolidator.

T1049
System Network Connections Discovery
GroupTurla

Turla surveys a system upon check-in to discover active local network connections using the netstat -an, net use, net file, and net session commands. Turla RPC backdoors have also enumerated the IPv4 TCP connection table via the GetTcpTable2 API call.

T1053.005
Scheduled Task
MalwareComRAT

ComRAT has used a scheduled task to launch its PowerShell loader.

T1055.001
Dynamic-link Library Injection
MalwareComRAT

ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process.

T1059.001
PowerShell
MalwareComRAT

ComRAT has used PowerShell to load itself every time a user logs in to the system. ComRAT can execute PowerShell scripts loaded into memory or from the file system.

T1059.003
Windows Command Shell
MalwareComRAT

ComRAT has used cmd.exe to execute commands.

T1069.001
Local Groups
GroupTurla

Turla has used net localgroup and net localgroup Administrators to enumerate group information, including members of the local administrators group.

T1069.002
Domain Groups
GroupTurla

Turla has used net group "Domain Admins" /domain to identify domain administrators.

T1071.001
Web Protocols
MalwareComRAT

ComRAT has used HTTP requests for command and control.

T1071.003
Mail Protocols
MalwareComRAT

ComRAT can use email attachments for command and control.

T1082
System Information Discovery
GroupTurla

Turla surveys a system upon check-in to discover operating system configuration details using the systeminfo and set commands.

T1083
File and Directory Discovery
GroupTurla

Turla surveys a system upon check-in to discover files in specific locations on the hard disk %TEMP% directory, the current user's desktop, the Program Files directory, and Recent. Turla RPC backdoors have also searched for files matching the lPH*.dll pattern.

T1087.001
Local Account
GroupTurla

Turla has used net user to enumerate local accounts on the system.

T1087.002
Domain Account
GroupTurla

Turla has used net user /domain to enumerate domain accounts.

T1102.002
Bidirectional Communication
MalwareComRAT

ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information.

T1106
Native API
MalwareComRAT

ComRAT can load a PE file from memory or the file system and execute it with CreateProcessW.

T1112
Modify Registry
MalwareComRAT

ComRAT has modified Registry values to store encrypted orchestrator code and payloads.

T1120
Peripheral Device Discovery
GroupTurla

Turla has used fsutil fsinfo drives to list connected drives.

T1140
Deobfuscate/Decode Files or Information
MalwareComRAT

ComRAT has used unique per machine passwords to decrypt the orchestrator payload and a hardcoded XOR key to decrypt its communications module. ComRAT has also used a unique password to decrypt the file used for its hidden file system.

T1189
Drive-by Compromise
GroupTurla

Turla has infected victims using watering holes.

T1201
Password Policy Discovery
GroupTurla

Turla has used net accounts and net accounts /domain to acquire password policy information.

T1213.006
Databases
GroupTurla

Turla has used a custom .NET tool to collect documents from an organization's internal central database.

T1518
Software Discovery
MalwareComRAT

ComRAT can check the victim's default browser to determine which process to inject its communications module into.

T1518.001
Security Software Discovery
GroupTurla

Turla has obtained information on security software, including security logging information that may indicate whether their malware has been detected.

T1564.005
Hidden File System
MalwareComRAT

ComRAT has used a portable FAT16 partition image placed in %TEMP% as a hidden file system.

T1567.002
Exfiltration to Cloud Storage
GroupTurla

Turla has used WebDAV to upload stolen USB files to a cloud drive. Turla has also exfiltrated stolen files to OneDrive and 4shared.

T1573.002
Asymmetric Cryptography
MalwareComRAT

ComRAT can use SSL/TLS encryption for its HTTP-based C2 channel. ComRAT has used public key cryptography with RSA and AES encrypted email attachments for its Gmail C2 channel.

T1615
Group Policy Discovery
GroupTurla

Turla surveys a system upon check-in to discover Group Policy details using the gpresult command.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.