ATT&CKReferencesSentinelOne Gootloader June 2021

SentinelOne Gootloader June 2021

Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareGootloader

Gootloader can use an embedded script to check the IP address of potential victims visiting compromised websites.

T1027
Obfuscated Files or Information
MalwareGootloader

The Gootloader first stage script is obfuscated using random alpha numeric strings.

T1055.012
Process Hollowing
MalwareGootloader

Gootloader can inject its Delphi executable into ImagingDevices.exe using a process hollowing technique.

T1059.001
PowerShell
MalwareGootloader

Gootloader can use an encoded PowerShell stager to write to the Registry for persistence.

T1059.007
JavaScript
MalwareGootloader

Gootloader can execute a Javascript file for initial infection.

T1069.002
Domain Groups
MalwareGootloader

Gootloader can determine if a targeted system is part of an Active Directory domain by expanding the %USERDNSDOMAIN% environment variable.

T1105
Ingress Tool Transfer
MalwareGootloader

Gootloader can fetch second stage code from hardcoded web domains.

T1132.001
Standard Encoding
MalwareGootloader

Gootloader can retrieve a Base64 encoded stager from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareGootloader

Gootloader has the ability to decode and decrypt malicious payloads prior to execution.

T1204.001
Malicious Link
MalwareGootloader

Gootloader has been executed through malicious links presented to users as internet search results.

T1584.001
Domains
MalwareGootloader

Gootloader has used compromised legitimate domains to as a delivery network for malicious payloads.

T1584.006
Web Services
MalwareGootloader

Gootloader can insert malicious scripts to compromise vulnerable content management systems (CMS).

T1614
System Location Discovery
MalwareGootloader

Gootloader can use IP geolocation to determine if the person browsing to a compromised site is within a targeted territory such as the US, Canada, Germany, and South Korea.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.