ATT&CKReferencesFireEye SUNSHUTTLE Mar 2021

FireEye SUNSHUTTLE Mar 2021

Smith, L., Leathery, J., Read, B. (2021, March 4). New SUNSHUTTLE Second-Stage Backdoor Uncovered Targeting U.S.-Based Entity; Possible Connection to UNC2452. Retrieved March 12, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareGoldMax

GoldMax has been packed for obfuscation.

T1027.013
Encrypted/Encoded File
MalwareGoldMax

GoldMax has written AES-encrypted and Base64-encoded configuration files to disk.

T1041
Exfiltration Over C2 Channel
MalwareGoldMax

GoldMax can exfiltrate files over the existing C2 channel.

T1059.003
Windows Command Shell
MalwareGoldMax

GoldMax can spawn a command shell, and execute native commands.

T1071.001
Web Protocols
MalwareGoldMax

GoldMax has used HTTPS and HTTP GET requests with custom HTTP cookies for C2.

T1105
Ingress Tool Transfer
MalwareGoldMax

GoldMax can download and execute additional files.

T1124
System Time Discovery
MalwareGoldMax

GoldMax can check the current date-time value of the compromised system, comparing it to the hardcoded execution trigger and can send the current timestamp to the C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwareGoldMax

GoldMax has decoded and decrypted the configuration file when executed.

T1497.001
System Checks
MalwareGoldMax

GoldMax will check if it is being run in a virtualized environment by comparing the collected MAC address to c8:27:cc:c2:37:5a.

T1583.001
Domains
CampaignSolarWinds Compromise

For the SolarWinds Compromise, APT29 acquired C2 domains, sometimes through resellers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.