Liebenberg, D.. (2018, August 30). Rocke: The Champion of Monero Miners. Retrieved May 26, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
GroupRocke | Rocke has looked for IP addresses in the known_hosts file on the infected system and attempted to SSH into them. |
| T1027.002 Software Packing |
GroupRocke | Rocke's miner has created UPX-packed files in the Windows Start Menu Folder. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupRocke | Rocke has used shell scripts which download mining executables and saves them with the filename "java". |
| T1046 Network Service Discovery |
GroupRocke | Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers. |
| T1053.003 Cron |
GroupRocke | Rocke installed a cron job that downloaded and executed files from the C2. |
| T1055.002 Portable Executable Injection |
GroupRocke | Rocke's miner, "TermsHost.exe", evaded defenses by injecting itself into Windows processes, including Notepad.exe. |
| T1059.004 Unix Shell |
GroupRocke | Rocke used shell scripts to run commands which would obtain persistence and execute the cryptocurrency mining malware. |
| T1071 Application Layer Protocol |
GroupRocke | Rocke issued wget requests from infected systems to the C2. |
| T1102 Web Service |
GroupRocke | Rocke has used Pastebin, Gitee, and GitLab for Command and Control. |
| T1105 Ingress Tool Transfer |
GroupRocke | Rocke used malware to download additional malicious files to the target system. |
| T1140 Deobfuscate/Decode Files or Information |
GroupRocke | Rocke has extracted tar.gz files after downloading them from a C2 server. |
| T1190 Exploit Public-Facing Application |
GroupRocke | Rocke exploited Apache Struts, Oracle WebLogic (CVE-2017-10271), and Adobe ColdFusion (CVE-2017-3066) vulnerabilities to deliver malware. |
| T1496.001 Compute Hijacking |
GroupRocke | Rocke has distributed cryptomining malware. |
| T1518.001 Security Software Discovery |
GroupRocke | Rocke used scripts which detected and uninstalled antivirus software. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupRocke | Rocke's miner has created UPX-packed files in the Windows Start Menu Folder. |
| T1564.001 Hidden Files and Directories |
GroupRocke | Rocke downloaded a file "libprocesshider", which could hide files on the target system. |
| T1685 Disable or Modify Tools |
GroupRocke | Rocke used scripts which detected and uninstalled antivirus software. |
| T1686 Disable or Modify System Firewall |
GroupRocke | Rocke used scripts which killed processes and added firewall rules to block traffic related to other cryptominers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.