Check Point Research Team. (2021, August 14). Indra - Hackers Behind Recent Attacks on Iran. Retrieved February 17, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.004 Masquerade Task or Service |
MalwareMeteor | Meteor has been disguised as the Windows Power Efficiency Diagnostics report tool. |
| T1047 Windows Management Instrumentation |
MalwareMeteor | Meteor can use `wmic.exe` as part of its effort to delete shadow copies. |
| T1053.005 Scheduled Task |
MalwareMeteor | Meteor execution begins from a scheduled task named `Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeAll` and it creates a separate scheduled task called `mstask` to run the wiper only once at 23:55:00. |
| T1057 Process Discovery |
MalwareMeteor | Meteor can check if a specific process is running, such as Kaspersky's `avp.exe`. |
| T1059.001 PowerShell |
MalwareMeteor | Meteor can use PowerShell commands to disable the network adapters on a victim machines. |
| T1059.003 Windows Command Shell |
MalwareMeteor | Meteor can run `set.bat`, `update.bat`, `cache.bat`, `bcd.bat`, `msrun.bat`, and similar scripts. |
| T1070.004 File Deletion |
MalwareMeteor | Meteor will delete the folder containing malicious scripts if it detects the hostname as `PIS-APP`, `PIS-MOB`, `WSUSPROXY`, or `PIS-DB`. |
| T1082 System Information Discovery |
MalwareMeteor | Meteor has the ability to discover the hostname of a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareMeteor | Meteor has the ability to download additional files for execution on the victim's machine. |
| T1106 Native API |
MalwareMeteor | Meteor can use `WinAPI` to remove a victim machine from an Active Directory domain. |
| T1484.001 Group Policy Modification |
MalwareMeteor | Meteor can use group policy to push a scheduled task from the AD to all network machines. |
| T1485 Data Destruction |
MalwareMeteor | Meteor can fill a victim's files and directories with zero-bytes in replacement of real content before deleting them. |
| T1489 Service Stop |
MalwareMeteor | Meteor can disconnect all network adapters on a compromised host using `powershell -Command "Get-WmiObject -class Win32_NetworkAdapter | ForEach { If ($.NetEnabled) { $.Disable() } }" > NUL`. |
| T1490 Inhibit System Recovery |
MalwareMeteor | Meteor can use `bcdedit` to delete different boot identifiers on a compromised host; it can also use `vssadmin.exe delete shadows /all /quiet` and `C:\\Windows\\system32\\wbem\\wmic.exe shadowcopy delete`. |
| T1491.001 Internal Defacement |
MalwareMeteor | Meteor can change both the desktop wallpaper and the lock screen image to a custom image. |
| T1518.001 Security Software Discovery |
MalwareMeteor | Meteor has the ability to search for Kaspersky Antivirus on a victim's machine. |
| T1531 Account Access Removal |
MalwareMeteor | Meteor has the ability to change the password of local users on compromised hosts and can log off users. |
| T1564.003 Hidden Window |
MalwareMeteor | Meteor can hide its console window upon execution to decrease its visibility to a victim. |
| T1685 Disable or Modify Tools |
MalwareMeteor | Meteor can attempt to uninstall Kaspersky Antivirus or remove the Kaspersky license; it can also add all files and folders related to the attack to the Windows Defender exclusion list. |
| T1685.005 Clear Windows Event Logs |
MalwareMeteor | Meteor can use Wevtutil to remove Security, System and Application Event Viewer logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.