ATT&CKReferencesFireEye POSHSPY April 2017

FireEye POSHSPY April 2017

Dunwoody, M.. (2017, April 3). Dissecting One of APT29’s Fileless WMI and PowerShell Backdoors (POSHSPY). Retrieved April 5, 2017.

Open the source

Techniques2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwarePOSHSPY

POSHSPY appends a file signature header (randomly selected from six file types) to encrypted data prior to upload or download.

T1030
Data Transfer Size Limits
MalwarePOSHSPY

POSHSPY uploads data in 2048-byte chunks.

T1059.001
PowerShell
MalwarePOSHSPY

POSHSPY uses PowerShell to execute various commands, one to execute its payload.

T1070.006
Timestomp
MalwarePOSHSPY

POSHSPY modifies timestamps of all downloaded executables to match a randomly selected file created prior to 2013.

T1105
Ingress Tool Transfer
MalwarePOSHSPY

POSHSPY downloads and executes additional PowerShell code and Windows binaries.

T1546.003
Windows Management Instrumentation Event Subscription
MalwarePOSHSPY

POSHSPY uses a WMI event subscription to establish persistence.

T1568.002
Domain Generation Algorithms
MalwarePOSHSPY

POSHSPY uses a DGA to derive command and control URLs from a word list.

T1573.002
Asymmetric Cryptography
MalwarePOSHSPY

POSHSPY encrypts C2 traffic with AES and RSA.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.