Falcone, R. (2018, January 25). OilRig uses RGDoor IIS Backdoor on Targets in the Middle East. Retrieved July 6, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareRGDoor | RGDoor executes the |
| T1059.003 Windows Command Shell |
MalwareRGDoor | RGDoor uses cmd.exe to execute commands on the victim’s machine. |
| T1071.001 Web Protocols |
MalwareRGDoor | RGDoor uses HTTP for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareRGDoor | RGDoor uploads and downloads files to and from the victim’s machine. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRGDoor | RGDoor decodes Base64 strings and decrypts strings using a custom XOR algorithm. |
| T1505.004 IIS Components |
MalwareRGDoor | RGDoor establishes persistence on webservers as an IIS module. |
| T1560.003 Archive via Custom Method |
MalwareRGDoor | RGDoor encrypts files with XOR before sending them back to the C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.