ANSSI. (2021, January 27). SANDWORM INTRUSION SET CAMPAIGN TARGETING CENTREON SYSTEMS. Retrieved March 30, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to copy files on a compromised host. |
| T1008 Fallback Channels |
MalwareExaramel for Linux | Exaramel for Linux can attempt to find a new C2 server if it receives an error. |
| T1027 Obfuscated Files or Information |
MalwareP.A.S. Webshell | P.A.S. Webshell can use encryption and base64 encoding to hide strings and to enforce access control once deployed. |
| T1027.013 Encrypted/Encoded File |
MalwareExaramel for Linux | Exaramel for Linux uses RC4 for encrypting the configuration. |
| T1033 System Owner/User Discovery |
MalwareExaramel for Linux | Exaramel for Linux can run |
| T1046 Network Service Discovery |
MalwareP.A.S. Webshell | P.A.S. Webshell can scan networks for open ports and listening services. |
| T1053.003 Cron |
MalwareExaramel for Linux | Exaramel for Linux uses crontab for persistence if it does not have root privileges. |
| T1059 Command and Scripting Interpreter |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to create reverse shells with Perl scripts. |
| T1059.004 Unix Shell |
MalwareExaramel for Linux | Exaramel for Linux has a command to execute a shell command on the system. |
| T1070.004 File Deletion |
MalwareExaramel for Linux | Exaramel for Linux can uninstall its persistence mechanism and delete its configuration file. |
| T1070.004 File Deletion |
MalwareP.A.S. Webshell | P.A.S. Webshell can delete scripts from a subdirectory of /tmp after they are run. |
| T1071.001 Web Protocols |
MalwareP.A.S. Webshell | P.A.S. Webshell can issue commands via HTTP POST. |
| T1071.001 Web Protocols |
MalwareExaramel for Linux | Exaramel for Linux uses HTTPS for C2 communications. |
| T1083 File and Directory Discovery |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to list files and file characteristics including extension, size, ownership, and permissions. |
| T1087.001 Local Account |
MalwareP.A.S. Webshell | P.A.S. Webshell can display the /etc/passwd file on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareP.A.S. Webshell | P.A.S. Webshell can upload and download files to and from compromised hosts. |
| T1105 Ingress Tool Transfer |
MalwareExaramel for Linux | Exaramel for Linux has a command to download a file from and to a remote C2 server. |
| T1110.001 Password Guessing |
MalwareP.A.S. Webshell | P.A.S. Webshell can use predefined users and passwords to execute brute force attacks against SSH, FTP, POP3, MySQL, MSSQL, and PostgreSQL services. |
| T1133 External Remote Services |
GroupSandworm Team | Sandworm Team has used Dropbear SSH with a hardcoded backdoor password to maintain persistence within the target network. Sandworm Team has also used VPN tunnels established in legitimate software company infrastructure to gain access to internal networks of that software company's users. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareExaramel for Linux | Exaramel for Linux can decrypt its configuration file. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareP.A.S. Webshell | P.A.S. Webshell can use a decryption mechanism to process a user supplied password and allow execution. |
| T1213.006 Databases |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to list and extract data from SQL databases. |
| T1222.002 Linux and Mac Permissions |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to modify file permissions. |
| T1505.003 Web Shell |
MalwareP.A.S. Webshell | P.A.S. Webshell can gain remote access and execution on target web servers. |
| T1505.003 Web Shell |
GroupSandworm Team | Sandworm Team has used webshells including P.A.S. Webshell to maintain access to victim networks. |
| T1518 Software Discovery |
MalwareP.A.S. Webshell | P.A.S. Webshell can list PHP server configuration details. |
| T1543 Create or Modify System Process |
MalwareExaramel for Linux | Exaramel for Linux has a hardcoded location that it uses to achieve persistence if the startup system is Upstart or System V and it is running as root. |
| T1543.002 Systemd Service |
MalwareExaramel for Linux | Exaramel for Linux has a hardcoded location under systemd that it uses to achieve persistence if it is running as root. |
| T1548.001 Setuid and Setgid |
MalwareExaramel for Linux | Exaramel for Linux can execute commands with high privileges via a specific binary with setuid functionality. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.