ATT&CKSoftwarePOWERSTATS

POWERSTATS

S0223

Malware.View on attack.mitre.org

About this malware

POWERSTATS is a PowerShell-based first stage backdoor used by MuddyWater.

Techniques used27

Procedure examples27

TechniqueProcedure example
T1005
Data from Local System

POWERSTATS can upload files from compromised hosts.

T1016
System Network Configuration Discovery

POWERSTATS can retrieve IP, network adapter configuration information, and domain from compromised hosts.

T1027.010
Command Obfuscation

POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation

T1027.016
Junk Code Insertion

POWERSTATS has used useless code blocks to counter analysis.

T1029
Scheduled Transfer

POWERSTATS can sleep for a given number of seconds.

T1033
System Owner/User Discovery

POWERSTATS has the ability to identify the username on the compromised host.

T1036.004
Masquerade Task or Service

POWERSTATS has created a scheduled task named "MicrosoftEdge" to establish persistence.

T1047
Windows Management Instrumentation

POWERSTATS can use WMI queries to retrieve data from compromised hosts.

T1053.005
Scheduled Task

POWERSTATS has established persistence through a scheduled task using the command ”C:\Windows\system32\schtasks.exe” /Create /F /SC DAILY /ST 12:00 /TN MicrosoftEdge /TR “c:\Windows\system32\wscript.exe C:\Windows\temp\Windows.vbe”.

T1057
Process Discovery

POWERSTATS has used get_tasklist to discover processes on the compromised host.

T1059.001
PowerShell

POWERSTATS uses PowerShell for obfuscation and execution.

T1059.005
Visual Basic

POWERSTATS can use VBScript (VBE) code for execution.

T1059.007
JavaScript

POWERSTATS can use JavaScript code for execution.

T1070.004
File Deletion

POWERSTATS can delete all files on the C:\, D:\, E:\ and, F:\ drives using PowerShell Remove-Item commands.

T1082
System Information Discovery

POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts.

View all 27 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit 42 MuddyWater Nov 2017 Open source
    Lancaster, T.. (2017, November 14). Muddying the Water: Targeted Attacks in the Middle East. Retrieved March 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.