Trend Micro. (2017, February 27). RATANKBA: Delving into Large-scale Watering Holes against Enterprises. Retrieved May 22, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareRATANKBA | RATANKBA uses |
| T1012 Query Registry |
MalwareRATANKBA | RATANKBA uses the command |
| T1016 System Network Configuration Discovery |
MalwareRATANKBA | RATANKBA gathers the victim’s IP address via the |
| T1018 Remote System Discovery |
MalwareRATANKBA | RATANKBA runs the |
| T1033 System Owner/User Discovery |
MalwareRATANKBA | RATANKBA runs the |
| T1047 Windows Management Instrumentation |
MalwareRATANKBA | RATANKBA uses WMI to perform process monitoring. |
| T1049 System Network Connections Discovery |
MalwareRATANKBA | RATANKBA uses |
| T1055.001 Dynamic-link Library Injection |
MalwareRATANKBA | RATANKBA performs a reflective DLL injection using a given pid. |
| T1057 Process Discovery |
MalwareRATANKBA | RATANKBA lists the system’s processes. |
| T1059.001 PowerShell |
MalwareRATANKBA | There is a variant of RATANKBA that uses a PowerShell script instead of the traditional PE form. |
| T1059.003 Windows Command Shell |
MalwareRATANKBA | RATANKBA uses cmd.exe to execute commands. |
| T1071.001 Web Protocols |
MalwareRATANKBA | RATANKBA uses HTTP/HTTPS for command and control communication. |
| T1082 System Information Discovery |
MalwareRATANKBA | RATANKBA gathers information about the OS architecture, OS name, and OS version/Service pack. |
| T1087.001 Local Account |
MalwareRATANKBA | RATANKBA uses the |
| T1105 Ingress Tool Transfer |
MalwareRATANKBA | RATANKBA uploads and downloads information. |
| T1189 Drive-by Compromise |
GroupLazarus Group | Lazarus Group delivered RATANKBA and other malicious code to victims via a compromised legitimate website. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.