Platt, J. and Reeves, J.. (2019, March). FIN7 Revisited: Inside Astra Panel and SQLRat Malware. Retrieved June 18, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwareSQLRat | SQLRat has used a character insertion obfuscation technique, making the script appear to contain Chinese characters. |
| T1053.005 Scheduled Task |
MalwareSQLRat | SQLRat has created scheduled tasks in |
| T1053.005 Scheduled Task |
GroupFIN7 | FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence. |
| T1059 Command and Scripting Interpreter |
GroupFIN7 | FIN7 used SQL scripts to help perform tasks on the victim's machine. |
| T1059.001 PowerShell |
MalwareSQLRat | SQLRat has used PowerShell to create a Meterpreter session. |
| T1059.003 Windows Command Shell |
MalwareSQLRat | SQLRat has used SQL to execute JavaScript and VB scripts on the host system. |
| T1059.003 Windows Command Shell |
GroupFIN7 | FIN7 used the command prompt to launch commands on the victim’s machine. Additionally, FIN7 has used cmd.exe to open the Run dialog by sending the “Windows + R” keys through malicious USBs acting as virtual keyboards. |
| T1059.005 Visual Basic |
GroupFIN7 | FIN7 used VBS scripts to help perform tasks on the victim's machine. |
| T1059.007 JavaScript |
GroupFIN7 | FIN7 used JavaScript scripts to help perform tasks on the victim's machine. |
| T1070.004 File Deletion |
MalwareSQLRat | SQLRat has used been observed deleting scripts once used. |
| T1105 Ingress Tool Transfer |
MalwareSQLRat | SQLRat can make a direct SQL connection to a Microsoft database controlled by the attackers, retrieve an item from the bindata table, then write and execute the file on disk. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSQLRat | SQLRat has scripts that are responsible for deobfuscating additional scripts. |
| T1204.002 Malicious File |
MalwareSQLRat | SQLRat relies on users clicking on an embedded image to execute the scripts. |
| T1566.001 Spearphishing Attachment |
GroupFIN7 | FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.