Quinn, J. (2019, March 25). The odd case of a Gh0stRAT variant. Retrieved July 15, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
Malwaregh0st RAT | gh0st RAT has checked for the existence of a Service key to determine if it has already been installed on the system. |
| T1055 Process Injection |
Malwaregh0st RAT | gh0st RAT can inject malicious code into process created by the “Command_Create&Inject” function. |
| T1056.001 Keylogging |
Malwaregh0st RAT | gh0st RAT has a keylogger. |
| T1070.004 File Deletion |
Malwaregh0st RAT | gh0st RAT has the capability to to delete files. |
| T1082 System Information Discovery |
Malwaregh0st RAT | gh0st RAT has gathered system architecture, processor, OS configuration, and installed hardware information. |
| T1095 Non-Application Layer Protocol |
Malwaregh0st RAT | gh0st RAT has used an encrypted protocol within TCP segments to communicate with the C2. |
| T1105 Ingress Tool Transfer |
Malwaregh0st RAT | gh0st RAT can download files to the victim’s machine. |
| T1106 Native API |
Malwaregh0st RAT | gh0st RAT has used the `InterlockedExchange`, `SeShutdownPrivilege`, and `ExitWindowsEx` Windows API functions. |
| T1112 Modify Registry |
Malwaregh0st RAT | gh0st RAT has altered the InstallTime subkey. |
| T1129 Shared Modules |
Malwaregh0st RAT | gh0st RAT can load DLLs into memory. |
| T1132.001 Standard Encoding |
Malwaregh0st RAT | gh0st RAT has used Zlib to compress C2 communications data before encrypting it. |
| T1140 Deobfuscate/Decode Files or Information |
Malwaregh0st RAT | gh0st RAT has decrypted and loaded the gh0st RAT DLL into memory, once the initial dropper executable is launched. |
| T1543.003 Windows Service |
Malwaregh0st RAT | gh0st RAT can create a new service to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
Malwaregh0st RAT | gh0st RAT has added a Registry Run key to establish persistence. |
| T1568.001 Fast Flux DNS |
Malwaregh0st RAT | gh0st RAT operators have used dynamic DNS to mask the true location of their C2 behind rapidly changing IP addresses. |
| T1569.002 Service Execution |
Malwaregh0st RAT | gh0st RAT can execute its service if the Service key exists. If the key does not exist, gh0st RAT will create and run the service. |
| T1573 Encrypted Channel |
Malwaregh0st RAT | gh0st RAT has encrypted TCP communications to evade detection. |
| T1685.005 Clear Windows Event Logs |
Malwaregh0st RAT | gh0st RAT is able to wipe event logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.