Schwarz, D. and Proofpoint Staff. (2019, January 9). ServHelper and FlawedGrace - New malware introduced by TA505. Retrieved May 28, 2019.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
MalwareServHelper | ServHelper has commands for adding a remote desktop user and sending RDP traffic to the attacker through a reverse SSH tunnel. |
| T1027.013 Encrypted/Encoded File |
MalwareFlawedGrace | FlawedGrace encrypts its C2 configuration files with AES in CBC mode. |
| T1033 System Owner/User Discovery |
MalwareServHelper | ServHelper will attempt to enumerate the username of the victim. |
| T1036.010 Masquerade Account Name |
MalwareServHelper | ServHelper has created a new user named `supportaccount`. |
| T1053.005 Scheduled Task |
MalwareServHelper | ServHelper contains modules that will use schtasks to carry out malicious operations. |
| T1059.003 Windows Command Shell |
MalwareServHelper | ServHelper can execute shell commands against cmd. |
| T1070.004 File Deletion |
MalwareServHelper | ServHelper has a module to delete itself from the infected machine. |
| T1071.001 Web Protocols |
MalwareServHelper | ServHelper uses HTTP for C2. |
| T1082 System Information Discovery |
MalwareServHelper | ServHelper will attempt to enumerate Windows version and system architecture. |
| T1098.007 Additional Local or Domain Groups |
MalwareServHelper | ServHelper has added a user named "supportaccount" to the Remote Desktop Users and Administrators groups. |
| T1105 Ingress Tool Transfer |
MalwareServHelper | ServHelper may download additional files to execute. |
| T1136.001 Local Account |
MalwareServHelper | ServHelper has created a new user named "supportaccount". |
| T1204.001 Malicious Link |
GroupTA505 | TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1204.002 Malicious File |
GroupTA505 | TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1566.001 Spearphishing Attachment |
GroupTA505 | TA505 has used spearphishing emails with malicious attachments to initially compromise victims. |
| T1566.002 Spearphishing Link |
GroupTA505 | TA505 has sent spearphishing emails containing malicious links. |
| T1573.002 Asymmetric Cryptography |
MalwareServHelper | ServHelper may set up a reverse SSH tunnel to give the attacker access to services running on the victim, such as RDP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.