4H RAT

S0065

Malware.View on attack.mitre.org

About this malware

4H RAT is malware that has been used by Putter Panda since at least 2007.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1057
Process Discovery

4H RAT has the capability to obtain a listing of running processes (including loaded modules).

T1059.003
Windows Command Shell

4H RAT has the capability to create a remote shell.

T1071.001
Web Protocols

4H RAT uses HTTP for command and control.

T1082
System Information Discovery

4H RAT sends an OS version identifier in its beacons.

T1083
File and Directory Discovery

4H RAT has the capability to obtain file and directory listings.

T1573.001
Symmetric Cryptography

4H RAT obfuscates C2 communication using a 1-byte XOR with the key 0xBE.

Groups that use it1

Campaigns0

None recorded.

References1

  1. CrowdStrike Putter Panda Open source
    Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.