ATT&CKReferencesTrendMicro POWERSTATS V3 June 2019

TrendMicro POWERSTATS V3 June 2019

Lunghi, D. and Horejsi, J.. (2019, June 10). MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools. Retrieved May 14, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwarePOWERSTATS

POWERSTATS can retrieve IP, network adapter configuration information, and domain from compromised hosts.

T1016
System Network Configuration Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the domain of the compromised host.

T1027.010
Command Obfuscation
MalwarePOWERSTATS

POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation

T1027.010
Command Obfuscation
MalwareSHARPSTATS

SHARPSTATS has used base64 encoding and XOR to obfuscate PowerShell scripts.

T1027.016
Junk Code Insertion
MalwarePOWERSTATS

POWERSTATS has used useless code blocks to counter analysis.

T1033
System Owner/User Discovery
MalwarePOWERSTATS

POWERSTATS has the ability to identify the username on the compromised host.

T1033
System Owner/User Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the username on the compromised host.

T1057
Process Discovery
MalwarePOWERSTATS

POWERSTATS has used get_tasklist to discover processes on the compromised host.

T1059.001
PowerShell
MalwareSHARPSTATS

SHARPSTATS has the ability to employ a custom PowerShell script.

T1059.001
PowerShell
MalwarePOWERSTATS

POWERSTATS uses PowerShell for obfuscation and execution.

T1059.005
Visual Basic
MalwarePOWERSTATS

POWERSTATS can use VBScript (VBE) code for execution.

T1082
System Information Discovery
MalwarePOWERSTATS

POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts.

T1082
System Information Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the IP address, machine name, and OS of the compromised host.

T1105
Ingress Tool Transfer
MalwareSHARPSTATS

SHARPSTATS has the ability to upload and download files.

T1113
Screen Capture
MalwarePOWERSTATS

POWERSTATS can retrieve screenshots from compromised hosts.

T1124
System Time Discovery
MalwareSHARPSTATS

SHARPSTATS has the ability to identify the current date and time on the compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.