ATT&CKReferencesUnit 42 RGDoor Jan 2018

Unit 42 RGDoor Jan 2018

Falcone, R. (2018, January 25). OilRig uses RGDoor IIS Backdoor on Targets in the Middle East. Retrieved July 6, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareRGDoor

RGDoor executes the whoami on the victim’s machine.

T1059.003
Windows Command Shell
MalwareRGDoor

RGDoor uses cmd.exe to execute commands on the victim’s machine.

T1071.001
Web Protocols
MalwareRGDoor

RGDoor uses HTTP for C2 communications.

T1105
Ingress Tool Transfer
MalwareRGDoor

RGDoor uploads and downloads files to and from the victim’s machine.

T1140
Deobfuscate/Decode Files or Information
MalwareRGDoor

RGDoor decodes Base64 strings and decrypts strings using a custom XOR algorithm.

T1505.004
IIS Components
MalwareRGDoor

RGDoor establishes persistence on webservers as an IIS module.

T1560.003
Archive via Custom Method
MalwareRGDoor

RGDoor encrypts files with XOR before sending them back to the C2 server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.