Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwarePOSHSPY | POSHSPY appends a file signature header (randomly selected from six file types) to encrypted data prior to upload or download. |
| T1030 Data Transfer Size Limits |
MalwarePOSHSPY | POSHSPY uploads data in 2048-byte chunks. |
| T1059.001 PowerShell |
MalwarePOSHSPY | POSHSPY uses PowerShell to execute various commands, one to execute its payload. |
| T1070.006 Timestomp |
MalwarePOSHSPY | POSHSPY modifies timestamps of all downloaded executables to match a randomly selected file created prior to 2013. |
| T1105 Ingress Tool Transfer |
MalwarePOSHSPY | POSHSPY downloads and executes additional PowerShell code and Windows binaries. |
| T1546.003 Windows Management Instrumentation Event Subscription |
MalwarePOSHSPY | POSHSPY uses a WMI event subscription to establish persistence. |
| T1568.002 Domain Generation Algorithms |
MalwarePOSHSPY | POSHSPY uses a DGA to derive command and control URLs from a word list. |
| T1573.002 Asymmetric Cryptography |
MalwarePOSHSPY | POSHSPY encrypts C2 traffic with AES and RSA. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.