Mercer, W. Rascagneres, P. Ventura, V. (2020, October 6). PoetRAT: Malware targeting public and private sector in Azerbaijan evolves . Retrieved April 9, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwarePoetRAT | PoetRAT has `pyminifier` to obfuscate scripts. |
| T1041 Exfiltration Over C2 Channel |
MalwarePoetRAT | PoetRAT has exfiltrated data over the C2 channel. |
| T1059.003 Windows Command Shell |
MalwarePoetRAT | PoetRAT has called cmd through a Word document macro. |
| T1059.005 Visual Basic |
MalwarePoetRAT | PoetRAT has used Word documents with VBScripts to execute malicious activities. |
| T1059.011 Lua |
MalwarePoetRAT | PoetRAT has executed a Lua script through a Lua interpreter for Windows. |
| T1071.001 Web Protocols |
MalwarePoetRAT | PoetRAT has used HTTP and HTTPs for C2 communications. |
| T1071.002 File Transfer Protocols |
MalwarePoetRAT | PoetRAT has used FTP for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwarePoetRAT | PoetRAT has the ability to copy files and download/upload files into C2 channels using FTP and HTTPS. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePoetRAT | PoetRAT has used LZMA and base64 libraries to decode obfuscated scripts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.