ATT&CKReferencesProofpoint TA505 Jan 2019

Proofpoint TA505 Jan 2019

Schwarz, D. and Proofpoint Staff. (2019, January 9). ServHelper and FlawedGrace - New malware introduced by TA505. Retrieved May 28, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
MalwareServHelper

ServHelper has commands for adding a remote desktop user and sending RDP traffic to the attacker through a reverse SSH tunnel.

T1027.013
Encrypted/Encoded File
MalwareFlawedGrace

FlawedGrace encrypts its C2 configuration files with AES in CBC mode.

T1033
System Owner/User Discovery
MalwareServHelper

ServHelper will attempt to enumerate the username of the victim.

T1036.010
Masquerade Account Name
MalwareServHelper

ServHelper has created a new user named `supportaccount`.

T1053.005
Scheduled Task
MalwareServHelper

ServHelper contains modules that will use schtasks to carry out malicious operations.

T1059.003
Windows Command Shell
MalwareServHelper

ServHelper can execute shell commands against cmd.

T1070.004
File Deletion
MalwareServHelper

ServHelper has a module to delete itself from the infected machine.

T1071.001
Web Protocols
MalwareServHelper

ServHelper uses HTTP for C2.

T1082
System Information Discovery
MalwareServHelper

ServHelper will attempt to enumerate Windows version and system architecture.

T1098.007
Additional Local or Domain Groups
MalwareServHelper

ServHelper has added a user named "supportaccount" to the Remote Desktop Users and Administrators groups.

T1105
Ingress Tool Transfer
MalwareServHelper

ServHelper may download additional files to execute.

T1136.001
Local Account
MalwareServHelper

ServHelper has created a new user named "supportaccount".

T1204.001
Malicious Link
GroupTA505

TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1204.002
Malicious File
GroupTA505

TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files.

T1566.001
Spearphishing Attachment
GroupTA505

TA505 has used spearphishing emails with malicious attachments to initially compromise victims.

T1566.002
Spearphishing Link
GroupTA505

TA505 has sent spearphishing emails containing malicious links.

T1573.002
Asymmetric Cryptography
MalwareServHelper

ServHelper may set up a reverse SSH tunnel to give the attacker access to services running on the victim, such as RDP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.