Malware.View on attack.mitre.org
ADVSTORESHELL is a spying backdoor that has been used by APT28 from at least 2012 to 2016. It is generally used for long-term espionage and is deployed on targets deemed interesting after a reconnaissance phase.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
ADVSTORESHELL can enumerate registry keys. |
| T1027 Obfuscated Files or Information |
Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory. |
| T1029 Scheduled Transfer |
ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes. |
| T1041 Exfiltration Over C2 Channel |
ADVSTORESHELL exfiltrates data over the same channel used for C2. |
| T1056.001 Keylogging |
ADVSTORESHELL can perform keylogging. |
| T1057 Process Discovery |
ADVSTORESHELL can list running processes. |
| T1059.003 Windows Command Shell |
ADVSTORESHELL can create a remote shell and run a given command. |
| T1070.004 File Deletion |
ADVSTORESHELL can delete files and directories. |
| T1071.001 Web Protocols |
ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs. |
| T1074.001 Local Data Staging |
ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory. |
| T1082 System Information Discovery |
ADVSTORESHELL can run Systeminfo to gather information about the victim. |
| T1083 File and Directory Discovery |
ADVSTORESHELL can list files and directories. |
| T1106 Native API |
ADVSTORESHELL is capable of starting a process using CreateProcess. |
| T1112 Modify Registry |
ADVSTORESHELL is capable of setting and deleting Registry values. |
| T1120 Peripheral Device Discovery |
ADVSTORESHELL can list connected devices. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.