ATT&CKReferencesAnomali Linux Rabbit 2018

Anomali Linux Rabbit 2018

Anomali Labs. (2018, December 6). Pulling Linux Rabbit/Rabbot Malware Out of a Hat. Retrieved March 4, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareLinux Rabbit

Linux Rabbit opens a socket on port 22 and if it receives a response it attempts to obtain the machine's hostname and Top-Level Domain.

T1078
Valid Accounts
MalwareLinux Rabbit

Linux Rabbit acquires valid SSH accounts through brute force.

T1110.003
Password Spraying
MalwareLinux Rabbit

Linux Rabbit brute forces SSH passwords in order to attempt to gain access and install its malware onto the server.

T1132
Data Encoding
MalwareLinux Rabbit

Linux Rabbit sends the payload from the C2 server as an encoded URL parameter.

T1133
External Remote Services
MalwareLinux Rabbit

Linux Rabbit attempts to gain access to the server via SSH.

T1546.004
Unix Shell Configuration Modification
MalwareLinux Rabbit

Linux Rabbit maintains persistence on an infected machine through rc.local and .bashrc files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.