ATT&CKReferencesFireEye APT34 Webinar Dec 2017

FireEye APT34 Webinar Dec 2017

Davis, S. and Caban, D. (2017, December 19). APT34 - New Targeted Attack in the Middle East. Retrieved December 20, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples25

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupOilRig

OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.004
LSA Secrets
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.005
Cached Domain Credentials
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1021.001
Remote Desktop Protocol
GroupOilRig

OilRig has used Remote Desktop Protocol for lateral movement. The group has also used tunneling tools to tunnel RDP into the environment.

T1046
Network Service Discovery
GroupOilRig

OilRig has used the publicly available tool SoftPerfect Network Scanner as well as a custom tool called GOLDIRONY to conduct network scanning.

T1047
Windows Management Instrumentation
GroupOilRig

OilRig has used WMI for execution.

T1056.001
Keylogging
GroupOilRig

OilRig has employed keyloggers including KEYPUNCH and LONGWATCH.

T1059.003
Windows Command Shell
MalwareSEASHARPEE

SEASHARPEE can execute commands on victims.

T1070.006
Timestomp
MalwareSEASHARPEE

SEASHARPEE can timestomp files on victims using a Web shell.

T1071.001
Web Protocols
MalwarePOWRUNER

POWRUNER can use HTTP for C2 communications.

T1071.001
Web Protocols
GroupOilRig

OilRig has used HTTP for C2.

T1071.004
DNS
MalwarePOWRUNER

POWRUNER can use DNS for C2 communications.

T1071.004
DNS
GroupOilRig

OilRig has used DNS for C2 including the publicly available requestbin.net tunneling service.

T1078
Valid Accounts
GroupOilRig

OilRig has used compromised credentials to access other systems on a victim network.

T1105
Ingress Tool Transfer
MalwareSEASHARPEE

SEASHARPEE can download remote files onto victims.

T1110
Brute Force
GroupOilRig

OilRig has used brute force techniques to obtain credentials.

T1113
Screen Capture
GroupOilRig

OilRig has a tool called CANDYKING to capture a screenshot of user's desktop.

T1133
External Remote Services
GroupOilRig

OilRig uses remote services such as VPN, Citrix, or OWA to persist in an environment.

T1505.003
Web Shell
GroupOilRig

OilRig has used web shells, often to maintain access to a victim network.

T1505.003
Web Shell
MalwareSEASHARPEE

SEASHARPEE is a Web shell.

T1552.001
Credentials In Files
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1555
Credentials from Password Stores
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1555.003
Credentials from Web Browsers
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers.

T1572
Protocol Tunneling
GroupOilRig

OilRig has used the Plink utility and other tools to create tunnels to C2 servers.

T1573.002
Asymmetric Cryptography
GroupOilRig

OilRig used the PowerExchange utility and other tools to create tunnels to C2 servers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.