Pantazopoulos, N.. (2018, November 8). RokRat Analysis. Retrieved May 21, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareROKRAT | ROKRAT can collect host data and specific file types. |
| T1057 Process Discovery |
MalwareROKRAT | ROKRAT can list the current running processes on the system. |
| T1070.004 File Deletion |
MalwareROKRAT | ROKRAT can request to delete files. |
| T1071.001 Web Protocols |
MalwareROKRAT | ROKRAT can use HTTP and HTTPS for command and control communication. |
| T1082 System Information Discovery |
MalwareROKRAT | ROKRAT can gather the hostname and the OS version to ensure it doesn’t run on a Windows XP or Windows Server 2003 systems. |
| T1083 File and Directory Discovery |
MalwareROKRAT | ROKRAT has the ability to gather a list of files and directories on the infected system. |
| T1105 Ingress Tool Transfer |
MalwareROKRAT | ROKRAT can retrieve additional malicious payloads from its C2 server. |
| T1113 Screen Capture |
MalwareROKRAT | ROKRAT can capture screenshots of the infected system using the `gdi32` library. |
| T1497.001 System Checks |
MalwareROKRAT | ROKRAT can check for VMware-related files and DLLs related to sandboxes. |
| T1622 Debugger Evasion |
MalwareROKRAT | ROKRAT can check for debugging tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.