ATT&CKReferencesPalo Alto Reaver Nov 2017

Palo Alto Reaver Nov 2017

Grunzweig, J. and Miller-Osborn, J. (2017, November 10). New Malware with Ties to SunOrcal Discovered. Retrieved November 16, 2017.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareReaver

Reaver queries the Registry to determine the correct Startup path to use for persistence.

T1016
System Network Configuration Discovery
MalwareReaver

Reaver collects the victim's IP address.

T1027.013
Encrypted/Encoded File
MalwareReaver

Reaver encrypts some of its files with XOR.

T1033
System Owner/User Discovery
MalwareReaver

Reaver collects the victim's username.

T1070.004
File Deletion
MalwareReaver

Reaver deletes the original dropped file from the victim.

T1071.001
Web Protocols
MalwareReaver

Some Reaver variants use HTTP for C2.

T1082
System Information Discovery
MalwareReaver

Reaver collects system information from the victim, including CPU speed, computer name, ANSI code page, OEM code page identifier for the OS, Microsoft Windows version, and memory information.

T1095
Non-Application Layer Protocol
MalwareReaver

Some Reaver variants use raw TCP for C2.

T1218.002
Control Panel
MalwareReaver

Reaver drops and executes a malicious CPL file as its payload.

T1543.003
Windows Service
MalwareReaver

Reaver installs itself as a new service.

T1547.001
Registry Run Keys / Startup Folder
MalwareReaver

Reaver creates a shortcut file and saves it in a Startup folder to establish persistence.

T1547.009
Shortcut Modification
MalwareReaver

Reaver creates a shortcut file and saves it in a Startup folder to establish persistence.

T1560.003
Archive via Custom Method
MalwareReaver

Reaver encrypts collected data with an incremental XOR key prior to exfiltration.

T1680
Local Storage Discovery
MalwareReaver

Reaver collects volume serial number from the victim.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.