Miller-Osborn, J. and Grunzweig, J.. (2017, March 30). Trochilus and New MoonWind RATs Used In Attack Against Thai Organizations. Retrieved March 30, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareMoonWind | MoonWind obtains the victim IP address. |
| T1033 System Owner/User Discovery |
MalwareMoonWind | MoonWind obtains the victim username. |
| T1056.001 Keylogging |
MalwareMoonWind | MoonWind has a keylogger. |
| T1057 Process Discovery |
MalwareMoonWind | MoonWind has a command to return a list of running processes. |
| T1059.003 Windows Command Shell |
MalwareMoonWind | MoonWind can execute commands via an interactive command shell. MoonWind uses batch scripts for various purposes, including to restart and uninstall itself. |
| T1070.004 File Deletion |
MalwareMoonWind | MoonWind can delete itself or specified files. |
| T1074.001 Local Data Staging |
MalwareMoonWind | MoonWind saves information from its keylogging routine as a .zip file in the present working directory. |
| T1082 System Information Discovery |
MalwareMoonWind | MoonWind can obtain the victim hostname, Windows version, RAM amount, and screen resolution. |
| T1083 File and Directory Discovery |
MalwareMoonWind | MoonWind has a command to return a directory listing for a specified directory. |
| T1095 Non-Application Layer Protocol |
MalwareMoonWind | MoonWind completes network communication via raw sockets. |
| T1120 Peripheral Device Discovery |
MalwareMoonWind | MoonWind obtains the number of removable drives from the victim. |
| T1124 System Time Discovery |
MalwareMoonWind | MoonWind obtains the victim's current time. |
| T1543.003 Windows Service |
MalwareMoonWind | MoonWind installs itself as a new service with automatic startup to establish persistence. The service checks every 60 seconds to determine if the malware is running; if not, it will spawn a new instance. |
| T1571 Non-Standard Port |
MalwareMoonWind | MoonWind communicates over ports 80, 443, 53, and 8080 via raw sockets instead of the protocols usually associated with the ports. |
| T1573.001 Symmetric Cryptography |
MalwareMoonWind | MoonWind encrypts C2 traffic using RC4 with a static key. |
| T1680 Local Storage Discovery |
MalwareSUGARUSH | MoonWind can obtain the number of drives on the victim machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.