ATT&CKReferencesPalo Alto MoonWind March 2017

Palo Alto MoonWind March 2017

Miller-Osborn, J. and Grunzweig, J.. (2017, March 30). Trochilus and New MoonWind RATs Used In Attack Against Thai Organizations. Retrieved March 30, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareMoonWind

MoonWind obtains the victim IP address.

T1033
System Owner/User Discovery
MalwareMoonWind

MoonWind obtains the victim username.

T1056.001
Keylogging
MalwareMoonWind

MoonWind has a keylogger.

T1057
Process Discovery
MalwareMoonWind

MoonWind has a command to return a list of running processes.

T1059.003
Windows Command Shell
MalwareMoonWind

MoonWind can execute commands via an interactive command shell. MoonWind uses batch scripts for various purposes, including to restart and uninstall itself.

T1070.004
File Deletion
MalwareMoonWind

MoonWind can delete itself or specified files.

T1074.001
Local Data Staging
MalwareMoonWind

MoonWind saves information from its keylogging routine as a .zip file in the present working directory.

T1082
System Information Discovery
MalwareMoonWind

MoonWind can obtain the victim hostname, Windows version, RAM amount, and screen resolution.

T1083
File and Directory Discovery
MalwareMoonWind

MoonWind has a command to return a directory listing for a specified directory.

T1095
Non-Application Layer Protocol
MalwareMoonWind

MoonWind completes network communication via raw sockets.

T1120
Peripheral Device Discovery
MalwareMoonWind

MoonWind obtains the number of removable drives from the victim.

T1124
System Time Discovery
MalwareMoonWind

MoonWind obtains the victim's current time.

T1543.003
Windows Service
MalwareMoonWind

MoonWind installs itself as a new service with automatic startup to establish persistence. The service checks every 60 seconds to determine if the malware is running; if not, it will spawn a new instance.

T1571
Non-Standard Port
MalwareMoonWind

MoonWind communicates over ports 80, 443, 53, and 8080 via raw sockets instead of the protocols usually associated with the ports.

T1573.001
Symmetric Cryptography
MalwareMoonWind

MoonWind encrypts C2 traffic using RC4 with a static key.

T1680
Local Storage Discovery
MalwareSUGARUSH

MoonWind can obtain the number of drives on the victim machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.