RATANKBA

Trend Micro. (2017, February 27). RATANKBA: Delving into Large-scale Watering Holes against Enterprises. Retrieved May 22, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareRATANKBA

RATANKBA uses tasklist /svc to display running tasks.

T1012
Query Registry
MalwareRATANKBA

RATANKBA uses the command reg query “HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\InternetSettings”.

T1016
System Network Configuration Discovery
MalwareRATANKBA

RATANKBA gathers the victim’s IP address via the ipconfig -all command.

T1018
Remote System Discovery
MalwareRATANKBA

RATANKBA runs the net view /domain and net view commands.

T1033
System Owner/User Discovery
MalwareRATANKBA

RATANKBA runs the whoami and query user commands.

T1047
Windows Management Instrumentation
MalwareRATANKBA

RATANKBA uses WMI to perform process monitoring.

T1049
System Network Connections Discovery
MalwareRATANKBA

RATANKBA uses netstat -ano to search for specific IP address ranges.

T1055.001
Dynamic-link Library Injection
MalwareRATANKBA

RATANKBA performs a reflective DLL injection using a given pid.

T1057
Process Discovery
MalwareRATANKBA

RATANKBA lists the system’s processes.

T1059.001
PowerShell
MalwareRATANKBA

There is a variant of RATANKBA that uses a PowerShell script instead of the traditional PE form.

T1059.003
Windows Command Shell
MalwareRATANKBA

RATANKBA uses cmd.exe to execute commands.

T1071.001
Web Protocols
MalwareRATANKBA

RATANKBA uses HTTP/HTTPS for command and control communication.

T1082
System Information Discovery
MalwareRATANKBA

RATANKBA gathers information about the OS architecture, OS name, and OS version/Service pack.

T1087.001
Local Account
MalwareRATANKBA

RATANKBA uses the net user command.

T1105
Ingress Tool Transfer
MalwareRATANKBA

RATANKBA uploads and downloads information.

T1189
Drive-by Compromise
GroupLazarus Group

Lazarus Group delivered RATANKBA and other malicious code to victims via a compromised legitimate website.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.