Malware.View on attack.mitre.org
Comnie is a remote backdoor which has been used in attacks in East Asia.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
Comnie runs the command: |
| T1016 System Network Configuration Discovery |
Comnie uses |
| T1018 Remote System Discovery |
Comnie runs the |
| T1027 Obfuscated Files or Information |
Comnie uses RC4 and Base64 to obfuscate strings. |
| T1027.001 Binary Padding |
Comnie appends a total of 64MB of garbage data to a file to deter any security products in place that may be scanning files on disk. |
| T1049 System Network Connections Discovery |
Comnie executes the |
| T1057 Process Discovery |
Comnie uses the |
| T1059.003 Windows Command Shell |
Comnie executes BAT scripts. |
| T1059.005 Visual Basic |
Comnie executes VBS scripts. |
| T1071.001 Web Protocols |
Comnie uses HTTP for C2 communication. |
| T1082 System Information Discovery |
Comnie collects the hostname of the victim machine. |
| T1087.001 Local Account |
Comnie uses the |
| T1102.002 Bidirectional Communication |
Comnie uses blogs and third-party sites (GitHub, tumbler, and BlogSpot) to avoid DNS-based blocking of their communication to the command and control server. |
| T1119 Automated Collection |
Comnie executes a batch script to store discovery information in %TEMP%\info.dat and then uploads the temporarily file to the remote C2 server. |
| T1218.011 Rundll32 |
Comnie uses Rundll32 to load a malicious DLL. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.