ATT&CKReferencesUS-CERT HARDRAIN March 2018

US-CERT HARDRAIN March 2018

US-CERT. (2018, February 05). Malware Analysis Report (MAR) - 10135536-F. Retrieved June 11, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareHARDRAIN

HARDRAIN uses cmd.exe to execute netshcommands.

T1090
Proxy
MalwareHARDRAIN

HARDRAIN uses the command cmd.exe /c netsh firewall add portopening TCP 443 "adp" and makes the victim machine function as a proxy server.

T1571
Non-Standard Port
MalwareHARDRAIN

HARDRAIN binds and listens on port 443 with a FakeTLS method.

T1686.003
Windows Host Firewall
MalwareHARDRAIN

HARDRAIN opens the Windows Firewall to modify incoming connections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.