OwaAuth

S0072

Malware.View on attack.mitre.org

About this malware

OwaAuth is a Web shell and credential stealer deployed to Microsoft Exchange servers that appears to be exclusively used by Threat Group-3390.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

OwaAuth uses the filename owaauth.dll, which is a legitimate file that normally resides in %ProgramFiles%\Microsoft\Exchange Server\ClientAccess\Owa\Auth\; the malicious file by the same name is saved in %ProgramFiles%\Microsoft\Exchange Server\ClientAccess\Owa\bin\.

T1056.001
Keylogging

OwaAuth captures and DES-encrypts credentials before writing the username and password to a log file, C:\log.txt.

T1070.006
Timestomp

OwaAuth has a command to timestop a file or directory.

T1071.001
Web Protocols

OwaAuth uses incoming HTTP requests with a username keyword and commands and handles them as instructions to perform actions.

T1083
File and Directory Discovery

OwaAuth has a command to list its directory and logical drives.

T1505.003
Web Shell

OwaAuth is a Web shell that appears to be exclusively used by Threat Group-3390. It is installed as an ISAPI filter on Exchange servers and shares characteristics with the China Chopper Web shell.

T1505.004
IIS Components

OwaAuth has been loaded onto Exchange servers and disguised as an ISAPI filter (owaauth.dll). The IIS w3wp.exe process then loads the malicious DLL.

T1560.003
Archive via Custom Method

OwaAuth DES-encrypts captured credentials using the key 12345678 before writing the credentials to a log file.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Dell TG-3390 Open source
    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.