ATT&CKReferencesDeep Instinct TA505 Apr 2019

Deep Instinct TA505 Apr 2019

Vilkomir-Preisman, S. (2019, April 2). New ServHelper Variant Employs Excel 4.0 Macro to Drop Signed Payload. Retrieved September 16, 2024..

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupTA505

TA505 has used base64 encoded PowerShell commands.

T1059.001
PowerShell
GroupTA505

TA505 has used PowerShell to download and execute malware and reconnaissance scripts.

T1059.003
Windows Command Shell
MalwareServHelper

ServHelper can execute shell commands against cmd.

T1070.004
File Deletion
MalwareServHelper

ServHelper has a module to delete itself from the infected machine.

T1105
Ingress Tool Transfer
GroupTA505

TA505 has downloaded additional malware to execute on victim systems.

T1105
Ingress Tool Transfer
MalwareServHelper

ServHelper may download additional files to execute.

T1218.007
Msiexec
GroupTA505

TA505 has used msiexec to download and execute malicious Windows Installer files.

T1218.011
Rundll32
GroupTA505

TA505 has leveraged rundll32.exe to execute malicious DLLs.

T1218.011
Rundll32
MalwareServHelper

ServHelper contains a module for downloading and executing DLLs that leverages rundll32.exe.

T1547.001
Registry Run Keys / Startup Folder
MalwareServHelper

ServHelper may attempt to establish persistence via the HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ run key.

T1553.002
Code Signing
GroupTA505

TA505 has signed payloads with code signing certificates from Thawte and Sectigo.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.