ATT&CKReferencesCofense Astaroth Sept 2018

Cofense Astaroth Sept 2018

Doaty, J., Garrett, P.. (2018, September 10). We’re Seeing a Resurgence of the Demonic Astaroth WMIC Trojan. Retrieved September 25, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareAstaroth

Astaroth collects the external IP address from the system.

T1047
Windows Management Instrumentation
MalwareAstaroth

Astaroth uses WMIC to execute payloads.

T1056.001
Keylogging
MalwareAstaroth

Astaroth logs keystrokes from the victim's machine.

T1059.007
JavaScript
MalwareAstaroth

Astaroth uses JavaScript to perform its core functionalities.

T1074.001
Local Data Staging
MalwareAstaroth

Astaroth collects data in a plaintext file named r1.log before exfiltration.

T1082
System Information Discovery
MalwareAstaroth

Astaroth collects the machine name and keyboard language from the system.

T1105
Ingress Tool Transfer
MalwareAstaroth

Astaroth uses certutil and BITSAdmin to download additional malware.

T1124
System Time Discovery
MalwareAstaroth

Astaroth collects the timestamp from the infected machine.

T1132.001
Standard Encoding
MalwareAstaroth

Astaroth encodes data using Base64 before sending it to the C2 server.

T1218.001
Compiled HTML File
MalwareAstaroth

Astaroth uses ActiveX objects for file execution and manipulation.

T1518.001
Security Software Discovery
MalwareAstaroth

Astaroth checks for the presence of Avast antivirus in the C:\Program\Files\ folder.

T1547.001
Registry Run Keys / Startup Folder
MalwareAstaroth

Astaroth creates a startup item for persistence.

T1547.009
Shortcut Modification
MalwareAstaroth

Astaroth's initial payload is a malicious .LNK file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.