Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwarePOWRUNER | POWRUNER may query the Registry by running |
| T1016 System Network Configuration Discovery |
MalwarePOWRUNER | POWRUNER may collect network configuration data by running |
| T1027.013 Encrypted/Encoded File |
GroupOilRig | OilRig has encrypted and encoded data in its malware, including by using base64. |
| T1033 System Owner/User Discovery |
MalwarePOWRUNER | POWRUNER may collect information about the currently logged in user by running |
| T1047 Windows Management Instrumentation |
MalwarePOWRUNER | POWRUNER may use WMI when collecting information about a victim. |
| T1049 System Network Connections Discovery |
MalwarePOWRUNER | POWRUNER may collect active network connections by running |
| T1053.005 Scheduled Task |
MalwarePOWRUNER | POWRUNER persists through a scheduled task that executes it every minute. |
| T1057 Process Discovery |
MalwarePOWRUNER | POWRUNER may collect process information by running |
| T1059 Command and Scripting Interpreter |
GroupOilRig | OilRig has used various types of scripting for execution. |
| T1059.001 PowerShell |
MalwareBONDUPDATER | BONDUPDATER is written in PowerShell. |
| T1059.001 PowerShell |
GroupOilRig | OilRig has used PowerShell scripts for execution, including use of a macro to run a PowerShell command to decode file contents. |
| T1059.001 PowerShell |
MalwarePOWRUNER | POWRUNER is written in PowerShell. |
| T1059.003 Windows Command Shell |
GroupOilRig | OilRig has used macros to deliver malware such as QUADAGENT and OopsIE. OilRig has used batch scripts. |
| T1059.003 Windows Command Shell |
MalwarePOWRUNER | POWRUNER can execute commands from its C2 server. |
| T1069.001 Local Groups |
MalwarePOWRUNER | POWRUNER may collect local group information by running |
| T1069.002 Domain Groups |
MalwarePOWRUNER | POWRUNER may collect domain group information by running |
| T1070.004 File Deletion |
GroupOilRig | OilRig has deleted files associated with their payload after execution. |
| T1071.001 Web Protocols |
MalwarePOWRUNER | POWRUNER can use HTTP for C2 communications. |
| T1071.004 DNS |
MalwarePOWRUNER | POWRUNER can use DNS for C2 communications. |
| T1082 System Information Discovery |
MalwarePOWRUNER | POWRUNER may collect information about the system by running |
| T1083 File and Directory Discovery |
MalwarePOWRUNER | POWRUNER may enumerate user directories on a victim. |
| T1087.002 Domain Account |
MalwarePOWRUNER | POWRUNER may collect user account information by running |
| T1105 Ingress Tool Transfer |
MalwarePOWRUNER | POWRUNER can download or upload files from its C2 server. |
| T1105 Ingress Tool Transfer |
GroupOilRig | OilRig had downloaded remote files onto victim infrastructure. |
| T1113 Screen Capture |
MalwarePOWRUNER | POWRUNER can capture a screenshot from a victim. |
| T1132.001 Standard Encoding |
MalwarePOWRUNER | POWRUNER can use base64 encoded C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
GroupOilRig | A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims. |
| T1518.001 Security Software Discovery |
MalwarePOWRUNER | POWRUNER may collect information on the victim's anti-virus software. |
| T1564.003 Hidden Window |
MalwareBONDUPDATER | BONDUPDATER uses |
| T1568.002 Domain Generation Algorithms |
MalwareBONDUPDATER | BONDUPDATER uses a DGA to communicate with command and control servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.