ATT&CKReferencesfsecure NanHaiShu July 2016

fsecure NanHaiShu July 2016

F-Secure Labs. (2016, July). NANHAISHU RATing the South China Sea. Retrieved July 6, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareNanHaiShu

NanHaiShu encodes files in Base64.

T1033
System Owner/User Discovery
MalwareNanHaiShu

NanHaiShu collects the username from the victim.

T1059.005
Visual Basic
MalwareNanHaiShu

NanHaiShu executes additional VBScript code on the victim's machine.

T1059.007
JavaScript
MalwareNanHaiShu

NanHaiShu executes additional Jscript code on the victim's machine.

T1070.004
File Deletion
MalwareNanHaiShu

NanHaiShu launches a script to delete their original decoy file to cover tracks.

T1071.004
DNS
MalwareNanHaiShu

NanHaiShu uses DNS for the C2 communications.

T1218.005
Mshta
MalwareNanHaiShu

NanHaiShu uses mshta.exe to load its program and files.

T1547.001
Registry Run Keys / Startup Folder
MalwareNanHaiShu

NanHaiShu modifies the %regrun% Registry to point itself to an autostart mechanism.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.