ATT&CKReferencesNCCGroup RokRat Nov 2018

NCCGroup RokRat Nov 2018

Pantazopoulos, N.. (2018, November 8). RokRat Analysis. Retrieved May 21, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareROKRAT

ROKRAT can collect host data and specific file types.

T1057
Process Discovery
MalwareROKRAT

ROKRAT can list the current running processes on the system.

T1070.004
File Deletion
MalwareROKRAT

ROKRAT can request to delete files.

T1071.001
Web Protocols
MalwareROKRAT

ROKRAT can use HTTP and HTTPS for command and control communication.

T1082
System Information Discovery
MalwareROKRAT

ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems.

T1083
File and Directory Discovery
MalwareROKRAT

ROKRAT has the ability to gather a list of files and directories on the infected system.

T1105
Ingress Tool Transfer
MalwareROKRAT

ROKRAT can retrieve additional malicious payloads from its C2 server.

T1113
Screen Capture
MalwareROKRAT

ROKRAT can capture screenshots of the infected system using the `gdi32` library.

T1497.001
System Checks
MalwareROKRAT

ROKRAT can check for VMware-related files and DLLs related to sandboxes.

T1622
Debugger Evasion
MalwareROKRAT

ROKRAT can check for debugging tools.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.