S2 Grupo. (2019, April 2). WIRTE Group attacking the Middle East. Retrieved May 24, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
GroupWIRTE | WIRTE has used PowerShell for script execution. |
| T1059.005 Visual Basic |
GroupWIRTE | WIRTE has used VBScript in its operations. |
| T1071.001 Web Protocols |
GroupWIRTE | WIRTE has used HTTP for network communication. |
| T1105 Ingress Tool Transfer |
GroupWIRTE | WIRTE has downloaded PowerShell code from the C2 server to be executed. |
| T1140 Deobfuscate/Decode Files or Information |
GroupWIRTE | WIRTE has used Base64 to decode malicious VBS script. |
| T1218.010 Regsvr32 |
GroupWIRTE | WIRTE has used `regsvr32.exe` to trigger the execution of a malicious script. |
| T1588.002 Tool |
GroupWIRTE | WIRTE has obtained and used Empire and Rclone for post-exploitation activities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.