ATT&CKReferencesCISA SoreFang July 2016

CISA SoreFang July 2016

CISA. (2020, July 16). MAR-10296782-1.v1 – SOREFANG. Retrieved September 29, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareSoreFang

SoreFang can collect the TCP/IP, DNS, DHCP, and network adapter configuration on a compromised host via ipconfig.exe /all.

T1027
Obfuscated Files or Information
MalwareSoreFang

SoreFang has the ability to encode and RC6 encrypt data sent to C2.

T1053.005
Scheduled Task
MalwareSoreFang

SoreFang can gain persistence through use of scheduled tasks.

T1057
Process Discovery
MalwareSoreFang

SoreFang can enumerate processes on a victim machine through use of Tasklist.

T1069.002
Domain Groups
MalwareSoreFang

SoreFang can enumerate domain groups by executing net.exe group /domain.

T1071.001
Web Protocols
MalwareSoreFang

SoreFang can use HTTP in C2 communications.

T1082
System Information Discovery
MalwareSoreFang

SoreFang can collect the hostname, operating system configuration, and product ID on victim machines by executing Systeminfo.

T1083
File and Directory Discovery
MalwareSoreFang

SoreFang has the ability to list directories.

T1087.001
Local Account
MalwareSoreFang

SoreFang can collect usernames from the local system via net.exe user.

T1087.002
Domain Account
MalwareSoreFang

SoreFang can enumerate domain accounts via net.exe user /domain.

T1105
Ingress Tool Transfer
MalwareSoreFang

SoreFang can download additional payloads from C2.

T1140
Deobfuscate/Decode Files or Information
MalwareSoreFang

SoreFang can decode and decrypt exfiltrated data sent to C2.

T1190
Exploit Public-Facing Application
MalwareSoreFang

SoreFang can gain access by exploiting a Sangfor SSL VPN vulnerability that allows for the placement and delivery of malicious update binaries.

T1680
Local Storage Discovery
MalwareSoreFang

SoreFang can collect disk space information on victim machines by executing Systeminfo.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.