OSInfo

S0165

Malware.View on attack.mitre.org

About this malware

OSInfo is a custom tool used by APT3 to do internal discovery on a victim's computer and network.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1012
Query Registry

OSInfo queries the registry to look for information about Terminal Services.

T1016
System Network Configuration Discovery

OSInfo discovers the current domain information.

T1018
Remote System Discovery

OSInfo performs a connection test to discover remote systems in the network

T1049
System Network Connections Discovery

OSInfo enumerates the current network connections similar to net use .

T1069.001
Local Groups

OSInfo has enumerated the local administrators group.

T1069.002
Domain Groups

OSInfo specifically looks for Domain Admins and power users within the domain.

T1082
System Information Discovery

OSInfo discovers information about the infected machine.

T1087.001
Local Account

OSInfo enumerates local and domain users

T1087.002
Domain Account

OSInfo enumerates local and domain users

T1135
Network Share Discovery

OSInfo discovers shares on the network

Groups that use it1

Campaigns0

None recorded.

References1

  1. Symantec Buckeye Open source
    Symantec Security Response. (2016, September 6). Buckeye cyberespionage group shifts gaze from US to Hong Kong. Retrieved September 26, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.