ATT&CKReferencesASERT Donot March 2018

ASERT Donot March 2018

Schwarz, D., Sopko J. (2018, March 08). Donot Team Leverages New Modular Malware Framework in South Asia. Retrieved June 11, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1005
Data from Local System
Malwareyty

yty collects files with the following extensions: .ppt, .pptx, .pdf, .doc, .docx, .xls, .xlsx, .docm, .rtf, .inp, .xlsm, .csv, .odt, .pps, .vcf and sends them back to the C2 server.

T1016
System Network Configuration Discovery
Malwareyty

yty runs ipconfig /all and collects the domain name.

T1018
Remote System Discovery
Malwareyty

yty uses the net view command for discovery.

T1027.002
Software Packing
Malwareyty

yty packs a plugin with UPX.

T1027.016
Junk Code Insertion
Malwareyty

yty contains junk code in its binary, likely to confuse malware analysts.

T1033
System Owner/User Discovery
Malwareyty

yty collects the victim’s username.

T1053.005
Scheduled Task
Malwareyty

yty establishes persistence by creating a scheduled task with the command SchTasks /Create /SC DAILY /TN BigData /TR “ + path_file + “/ST 09:30“.

T1056.001
Keylogging
Malwareyty

yty uses a keylogger plugin to gather keystrokes.

T1057
Process Discovery
Malwareyty

yty gets an output of running processes using the tasklist command.

T1082
System Information Discovery
Malwareyty

yty gathers the computer name, CPU information, Microsoft Windows version, and runs the command systeminfo.

T1083
File and Directory Discovery
Malwareyty

yty gathers information on victim’s drives and has a plugin for document listing.

T1102.002
Bidirectional Communication
Malwareyty

yty communicates to the C2 server by retrieving a Google Doc.

T1113
Screen Capture
Malwareyty

yty collects screenshots of the victim machine.

T1497.001
System Checks
Malwareyty

yty has some basic anti-sandbox detection that tries to detect Virtual PC, Sandboxie, and VMware.

T1680
Local Storage Discovery
Malwareyty

yty gathers the the serial number of the main disk volume.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.