Comnie

S0244

Malware.View on attack.mitre.org

About this malware

Comnie is a remote backdoor which has been used in attacks in East Asia.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1007
System Service Discovery

Comnie runs the command: net start >> %TEMP%\info.dat on a victim.

T1016
System Network Configuration Discovery

Comnie uses ipconfig /all and route PRINT to identify network adapter and interface information.

T1018
Remote System Discovery

Comnie runs the net view command

T1027
Obfuscated Files or Information

Comnie uses RC4 and Base64 to obfuscate strings.

T1027.001
Binary Padding

Comnie appends a total of 64MB of garbage data to a file to deter any security products in place that may be scanning files on disk.

T1049
System Network Connections Discovery

Comnie executes the netstat -ano command.

T1057
Process Discovery

Comnie uses the tasklist to view running processes on the victim’s machine.

T1059.003
Windows Command Shell

Comnie executes BAT scripts.

T1059.005
Visual Basic

Comnie executes VBS scripts.

T1071.001
Web Protocols

Comnie uses HTTP for C2 communication.

T1082
System Information Discovery

Comnie collects the hostname of the victim machine.

T1087.001
Local Account

Comnie uses the net user command.

T1102.002
Bidirectional Communication

Comnie uses blogs and third-party sites (GitHub, tumbler, and BlogSpot) to avoid DNS-based blocking of their communication to the command and control server.

T1119
Automated Collection

Comnie executes a batch script to store discovery information in %TEMP%\info.dat and then uploads the temporarily file to the remote C2 server.

T1218.011
Rundll32

Comnie uses Rundll32 to load a malicious DLL.

View all 19 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Palo Alto Comnie Open source
    Grunzweig, J. (2018, January 31). Comnie Continues to Target Organizations in East Asia. Retrieved June 7, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.