Anomali Labs. (2019, March 15). Rocke Evolves Its Arsenal With a New Malware Family Written in Golang. Retrieved April 24, 2019.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1014 Rootkit |
GroupRocke | Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists. |
| T1021.004 SSH |
GroupRocke | Rocke has spread its coinminer via SSH. |
| T1027 Obfuscated Files or Information |
GroupRocke | Rocke has modified UPX headers after packing files to break unpackers. |
| T1027.002 Software Packing |
GroupRocke | Rocke's miner has created UPX-packed files in the Windows Start Menu Folder. |
| T1027.004 Compile After Delivery |
GroupRocke | Rocke has compiled malware, delivered to victims as .c files, with the GNU Compiler Collection (GCC). |
| T1037 Boot or Logon Initialization Scripts |
GroupRocke | Rocke has installed an "init.d" startup script to maintain persistence. |
| T1046 Network Service Discovery |
GroupRocke | Rocke conducted scanning for exposed TCP port 7001 as well as SSH and Redis servers. |
| T1053.003 Cron |
GroupRocke | Rocke installed a cron job that downloaded and executed files from the C2. |
| T1057 Process Discovery |
GroupRocke | Rocke can detect a running process's PID on the infected machine. |
| T1059.006 Python |
GroupRocke | Rocke has used Python-based malware to install and spread their coinminer. |
| T1070.004 File Deletion |
GroupRocke | Rocke has deleted files on infected machines. |
| T1070.006 Timestomp |
GroupRocke | Rocke has changed the time stamp of certain files. |
| T1071.001 Web Protocols |
GroupRocke | Rocke has executed wget and curl commands to Pastebin over the HTTPS protocol. |
| T1082 System Information Discovery |
GroupRocke | Rocke has used uname -m to collect the name and information about the infected system's kernel. |
| T1102 Web Service |
GroupRocke | Rocke has used Pastebin, Gitee, and GitLab for Command and Control. |
| T1102.001 Dead Drop Resolver |
GroupRocke | Rocke has used Pastebin to check the version of beaconing malware and redirect to another Pastebin hosting updated malware. |
| T1222.002 Linux and Mac Permissions |
GroupRocke | Rocke has changed file permissions of files so they could not be modified. |
| T1543.002 Systemd Service |
GroupRocke | Rocke has installed a systemd service script to maintain persistence. |
| T1552.004 Private Keys |
GroupRocke | Rocke has used SSH private keys on the infected machine to spread its coinminer throughout a network. |
| T1571 Non-Standard Port |
GroupRocke | Rocke's miner connects to a C2 server using port 51640. |
| T1574.006 Dynamic Linker Hijacking |
GroupRocke | Rocke has modified /etc/ld.so.preload to hook libc functions in order to hide the installed dropper and mining software in process lists. |
| T1685.006 Clear Linux or Mac System Logs |
GroupRocke | Rocke has cleared log files within the /var/log/ folder. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.