Lunghi, D. and Horejsi, J.. (2019, June 10). MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools. Retrieved May 14, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwarePOWERSTATS | POWERSTATS can retrieve IP, network adapter configuration information, and domain from compromised hosts. |
| T1016 System Network Configuration Discovery |
MalwareSHARPSTATS | SHARPSTATS has the ability to identify the domain of the compromised host. |
| T1027.010 Command Obfuscation |
MalwarePOWERSTATS | POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation |
| T1027.010 Command Obfuscation |
MalwareSHARPSTATS | SHARPSTATS has used base64 encoding and XOR to obfuscate PowerShell scripts. |
| T1027.016 Junk Code Insertion |
MalwarePOWERSTATS | POWERSTATS has used useless code blocks to counter analysis. |
| T1033 System Owner/User Discovery |
MalwarePOWERSTATS | POWERSTATS has the ability to identify the username on the compromised host. |
| T1033 System Owner/User Discovery |
MalwareSHARPSTATS | SHARPSTATS has the ability to identify the username on the compromised host. |
| T1057 Process Discovery |
MalwarePOWERSTATS | POWERSTATS has used |
| T1059.001 PowerShell |
MalwareSHARPSTATS | SHARPSTATS has the ability to employ a custom PowerShell script. |
| T1059.001 PowerShell |
MalwarePOWERSTATS | POWERSTATS uses PowerShell for obfuscation and execution. |
| T1059.005 Visual Basic |
MalwarePOWERSTATS | POWERSTATS can use VBScript (VBE) code for execution. |
| T1082 System Information Discovery |
MalwarePOWERSTATS | POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts. |
| T1082 System Information Discovery |
MalwareSHARPSTATS | SHARPSTATS has the ability to identify the IP address, machine name, and OS of the compromised host. |
| T1105 Ingress Tool Transfer |
MalwareSHARPSTATS | SHARPSTATS has the ability to upload and download files. |
| T1113 Screen Capture |
MalwarePOWERSTATS | POWERSTATS can retrieve screenshots from compromised hosts. |
| T1124 System Time Discovery |
MalwareSHARPSTATS | SHARPSTATS has the ability to identify the current date and time on the compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.