CISA. (2020, October 29). Malware Analysis Report (AR20-303A). Retrieved December 9, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareComRAT | ComRAT has encrypted its virtual file system using AES-256 in XTS mode. |
| T1027.009 Embedded Payloads |
MalwareComRAT | ComRAT has embedded a XOR encrypted communications module inside the orchestrator module. |
| T1027.010 Command Obfuscation |
MalwareComRAT | ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts. |
| T1027.011 Fileless Storage |
MalwareComRAT | ComRAT has stored encrypted orchestrator code and payloads in the Registry. |
| T1053.005 Scheduled Task |
MalwareComRAT | ComRAT has used a scheduled task to launch its PowerShell loader. |
| T1055.001 Dynamic-link Library Injection |
MalwareComRAT | ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process. |
| T1059.001 PowerShell |
MalwareComRAT | ComRAT has used PowerShell to load itself every time a user logs in to the system. ComRAT can execute PowerShell scripts loaded into memory or from the file system. |
| T1071.001 Web Protocols |
MalwareComRAT | ComRAT has used HTTP requests for command and control. |
| T1102.002 Bidirectional Communication |
MalwareComRAT | ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information. |
| T1112 Modify Registry |
MalwareComRAT | ComRAT has modified Registry values to store encrypted orchestrator code and payloads. |
| T1124 System Time Discovery |
MalwareComRAT | ComRAT has checked the victim system's date and time to perform tasks during business hours (9 to 5, Monday to Friday). |
| T1140 Deobfuscate/Decode Files or Information |
MalwareComRAT | ComRAT has used unique per machine passwords to decrypt the orchestrator payload and a hardcoded XOR key to decrypt its communications module. ComRAT has also used a unique password to decrypt the file used for its hidden file system. |
| T1573.002 Asymmetric Cryptography |
MalwareComRAT | ComRAT can use SSL/TLS encryption for its HTTP-based C2 channel. ComRAT has used public key cryptography with RSA and AES encrypted email attachments for its Gmail C2 channel. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.