ATT&CKReferencesSymantec Orangeworm April 2018

Symantec Orangeworm April 2018

Symantec Security Response Attack Investigation Team. (2018, April 23). New Orangeworm attack group targets the healthcare sector in the U.S., Europe, and Asia. Retrieved May 8, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareKwampirs

Kwampirs collects a list of running services with the command tasklist /svc.

T1008
Fallback Channels
MalwareKwampirs

Kwampirs uses a large list of C2 servers that it cycles through until a successful connection is established.

T1016
System Network Configuration Discovery
MalwareKwampirs

Kwampirs collects network adapter and interface information by using the commands ipconfig /all, arp -a and route print. It also collects the system's MAC address with getmac and domain configuration with net config workstation.

T1018
Remote System Discovery
MalwareKwampirs

Kwampirs collects a list of available servers with the command net view.

T1021.002
SMB/Windows Admin Shares
MalwareKwampirs

Kwampirs copies itself over network shares to move laterally on a victim network.

T1021.002
SMB/Windows Admin Shares
GroupOrangeworm

Orangeworm has copied its backdoor across open network shares, including ADMIN$, C$WINDOWS, D$WINDOWS, and E$WINDOWS.

T1027.001
Binary Padding
MalwareKwampirs

Before writing to disk, Kwampirs inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections.

T1033
System Owner/User Discovery
MalwareKwampirs

Kwampirs collects registered owner details by using the commands systeminfo and net config workstation.

T1036.004
Masquerade Task or Service
MalwareKwampirs

Kwampirs establishes persistence by adding a new service with the display name "WMI Performance Adapter Extension" in an attempt to masquerade as a legitimate WMI service.

T1049
System Network Connections Discovery
MalwareKwampirs

Kwampirs collects a list of active and listening connections by using the command netstat -nao as well as a list of available network mappings with net use.

T1057
Process Discovery
MalwareKwampirs

Kwampirs collects a list of running services with the command tasklist /v.

T1069.001
Local Groups
MalwareKwampirs

Kwampirs collects a list of users belonging to the local users and administrators groups with the commands net localgroup administrators and net localgroup users.

T1069.002
Domain Groups
MalwareKwampirs

Kwampirs collects a list of domain groups with the command net localgroup /domain.

T1082
System Information Discovery
MalwareKwampirs

Kwampirs collects OS version information such as registered owner details, manufacturer details, processor type, available storage, installed patches, hostname, version info, system date, and other system information by using the commands systeminfo, net config workstation, hostname, ver, set, and date /t.

T1083
File and Directory Discovery
MalwareKwampirs

Kwampirs collects a list of files and directories in C:\ with the command dir /s /a c:\ >> "C:\windows\TEMP\[RANDOM].tmp".

T1087.001
Local Account
MalwareKwampirs

Kwampirs collects a list of accounts with the command net users.

T1135
Network Share Discovery
MalwareKwampirs

Kwampirs collects a list of network shares with the command net share.

T1140
Deobfuscate/Decode Files or Information
MalwareKwampirs

Kwampirs decrypts and extracts a copy of its main DLL payload when executing.

T1201
Password Policy Discovery
MalwareKwampirs

Kwampirs collects password policy information with the command net accounts.

T1218.011
Rundll32
MalwareKwampirs

Kwampirs uses rundll32.exe in a Registry value added to establish persistence.

T1543.003
Windows Service
MalwareKwampirs

Kwampirs creates a new service named WmiApSrvEx to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.