Lee, B., Falcone, R. (2019, January 18). DarkHydrus delivers new Trojan that can use Google Drive for C2 communications. Retrieved April 17, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareRogueRobin | RogueRobin uses various WMI queries to check if the sample is running in a sandbox. |
| T1059.001 PowerShell |
MalwareRogueRobin | RogueRobin uses a command prompt to run a PowerShell script from Excel. To assist in establishing persistence, RogueRobin creates |
| T1059.003 Windows Command Shell |
MalwareRogueRobin | RogueRobin uses Windows Script Components. |
| T1102.002 Bidirectional Communication |
MalwareRogueRobin | RogueRobin has used Google Drive as a Command and Control channel. |
| T1105 Ingress Tool Transfer |
MalwareRogueRobin | RogueRobin can save a new file to the system from the C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRogueRobin | RogueRobin decodes an embedded executable using base64 and decompresses it. |
| T1218.010 Regsvr32 |
MalwareRogueRobin | RogueRobin uses regsvr32.exe to run a .sct file for execution. |
| T1497.001 System Checks |
MalwareRogueRobin | RogueRobin uses WMI to check BIOS version for VBOX, bochs, qemu, virtualbox, and vm to check for evidence that the script might be executing within an analysis environment. |
| T1518.001 Security Software Discovery |
MalwareRogueRobin | RogueRobin enumerates running processes to search for Wireshark and Windows Sysinternals suite. |
| T1547.009 Shortcut Modification |
MalwareRogueRobin | RogueRobin establishes persistence by creating a shortcut (.LNK file) in the Windows startup folder to run a script each time the user logs in. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.