Anomali Labs. (2018, December 6). Pulling Linux Rabbit/Rabbot Malware Out of a Hat. Retrieved March 4, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareLinux Rabbit | Linux Rabbit opens a socket on port 22 and if it receives a response it attempts to obtain the machine's hostname and Top-Level Domain. |
| T1078 Valid Accounts |
MalwareLinux Rabbit | Linux Rabbit acquires valid SSH accounts through brute force. |
| T1110.003 Password Spraying |
MalwareLinux Rabbit | Linux Rabbit brute forces SSH passwords in order to attempt to gain access and install its malware onto the server. |
| T1132 Data Encoding |
MalwareLinux Rabbit | Linux Rabbit sends the payload from the C2 server as an encoded URL parameter. |
| T1133 External Remote Services |
MalwareLinux Rabbit | Linux Rabbit attempts to gain access to the server via SSH. |
| T1546.004 Unix Shell Configuration Modification |
MalwareLinux Rabbit | Linux Rabbit maintains persistence on an infected machine through rc.local and .bashrc files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.