Grunzweig, J. (2018, January 31). Comnie Continues to Target Organizations in East Asia. Retrieved June 7, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareComnie | Comnie runs the command: |
| T1016 System Network Configuration Discovery |
MalwareComnie | Comnie uses |
| T1027 Obfuscated Files or Information |
MalwareComnie | Comnie uses RC4 and Base64 to obfuscate strings. |
| T1027.001 Binary Padding |
MalwareComnie | Comnie appends a total of 64MB of garbage data to a file to deter any security products in place that may be scanning files on disk. |
| T1049 System Network Connections Discovery |
MalwareComnie | Comnie executes the |
| T1057 Process Discovery |
MalwareComnie | Comnie uses the |
| T1059.003 Windows Command Shell |
MalwareComnie | Comnie executes BAT scripts. |
| T1059.005 Visual Basic |
MalwareComnie | Comnie executes VBS scripts. |
| T1071.001 Web Protocols |
MalwareComnie | Comnie uses HTTP for C2 communication. |
| T1082 System Information Discovery |
MalwareComnie | Comnie collects the hostname of the victim machine. |
| T1087.001 Local Account |
MalwareComnie | Comnie uses the |
| T1102.002 Bidirectional Communication |
MalwareComnie | Comnie uses blogs and third-party sites (GitHub, tumbler, and BlogSpot) to avoid DNS-based blocking of their communication to the command and control server. |
| T1119 Automated Collection |
MalwareComnie | Comnie executes a batch script to store discovery information in %TEMP%\info.dat and then uploads the temporarily file to the remote C2 server. |
| T1218.011 Rundll32 |
MalwareComnie | Comnie uses Rundll32 to load a malicious DLL. |
| T1518.001 Security Software Discovery |
MalwareComnie | Comnie attempts to detect several anti-virus products. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareComnie | Comnie achieves persistence by adding a shortcut of itself to the startup path in the Registry. |
| T1547.009 Shortcut Modification |
MalwareComnie | Comnie establishes persistence via a .lnk file in the victim’s startup path. |
| T1573.001 Symmetric Cryptography |
MalwareComnie | Comnie encrypts command and control communications with RC4. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.