MSTIC. (2020, December 18). Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect customers . Retrieved January 5, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareSUNBURST | SUNBURST collected information from a compromised host. |
| T1027.015 Compression |
MalwareSUNBURST | SUNBURST strings were compressed and encoded in Base64. |
| T1033 System Owner/User Discovery |
MalwareSUNBURST | SUNBURST collected the username from a compromised host. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 renamed software and DLLs with legitimate names to appear benign. |
| T1059.001 PowerShell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands. |
| T1059.003 Windows Command Shell |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `cmd.exe` to execute commands on remote machines. |
| T1070.004 File Deletion |
MalwareSUNBURST | SUNBURST had a command to delete files. |
| T1082 System Information Discovery |
MalwareSUNBURST | SUNBURST collected hostname and OS version. |
| T1083 File and Directory Discovery |
MalwareSUNBURST | SUNBURST had commands to enumerate files and directories. |
| T1112 Modify Registry |
MalwareSUNBURST | SUNBURST had commands that allow an attacker to write or delete registry keys, and was observed stopping services by setting their |
| T1124 System Time Discovery |
MalwareSUNBURST | SUNBURST collected device `UPTIME`. |
| T1497.001 System Checks |
MalwareSUNBURST | SUNBURST checked the domain name of the compromised host to verify it was running in a real environment. |
| T1518.001 Security Software Discovery |
MalwareSUNBURST | SUNBURST checked for a variety of antivirus/endpoint detection agents prior to execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.