ATT&CKReferencesSymantec Remsec IOCs

Symantec Remsec IOCs

Symantec Security Response. (2016, August 8). Backdoor.Remsec indicators of compromise. Retrieved August 17, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareRemsec

Some data in Remsec is encrypted using RC5 in CBC mode, AES-CBC with a hardcoded key, RC4, or Salsa20. Some data is also base64-encoded.

T1056.001
Keylogging
MalwareRemsec

Remsec contains a keylogger component.

T1070.004
File Deletion
MalwareRemsec

Remsec is capable of deleting files on the victim. It also securely removes itself after collecting and exfiltrating data.

T1071.001
Web Protocols
MalwareRemsec

Remsec is capable of using HTTP and HTTPS for C2.

T1071.003
Mail Protocols
MalwareRemsec

Remsec is capable of using SMTP for C2.

T1071.004
DNS
MalwareRemsec

Remsec is capable of using DNS for C2.

T1083
File and Directory Discovery
MalwareRemsec

Remsec is capable of listing contents of folders on the victim. Remsec also searches for custom network encryption software on victims.

T1095
Non-Application Layer Protocol
MalwareRemsec

Remsec is capable of using ICMP, TCP, and UDP for C2.

T1105
Ingress Tool Transfer
MalwareRemsec

Remsec contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.