ATT&CKReferencesLab52 WIRTE Apr 2019

Lab52 WIRTE Apr 2019

S2 Grupo. (2019, April 2). WIRTE Group attacking the Middle East. Retrieved May 24, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1059.001
PowerShell
GroupWIRTE

WIRTE has used PowerShell for script execution.

T1059.005
Visual Basic
GroupWIRTE

WIRTE has used VBScript in its operations.

T1071.001
Web Protocols
GroupWIRTE

WIRTE has used HTTP for network communication.

T1105
Ingress Tool Transfer
GroupWIRTE

WIRTE has downloaded PowerShell code from the C2 server to be executed.

T1140
Deobfuscate/Decode Files or Information
GroupWIRTE

WIRTE has used Base64 to decode malicious VBS script.

T1218.010
Regsvr32
GroupWIRTE

WIRTE has used `regsvr32.exe` to trigger the execution of a malicious script.

T1588.002
Tool
GroupWIRTE

WIRTE has obtained and used Empire and Rclone for post-exploitation activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.