Malware.View on attack.mitre.org
RogueRobin is a payload used by DarkHydrus that has been developed in PowerShell and C#.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
RogueRobin gathers the IP address and domain from the victim’s machine. |
| T1027.010 Command Obfuscation |
The PowerShell script with the RogueRobin payload was obfuscated using the COMPRESS technique in `Invoke-Obfuscation`. |
| T1033 System Owner/User Discovery |
RogueRobin collects the victim’s username and whether that user is an admin. |
| T1047 Windows Management Instrumentation |
RogueRobin uses various WMI queries to check if the sample is running in a sandbox. |
| T1057 Process Discovery |
RogueRobin checks the running processes for evidence it may be running in a sandbox environment. It specifically enumerates processes for Wireshark and Sysinternals. |
| T1059.001 PowerShell |
RogueRobin uses a command prompt to run a PowerShell script from Excel. To assist in establishing persistence, RogueRobin creates |
| T1059.003 Windows Command Shell |
RogueRobin uses Windows Script Components. |
| T1082 System Information Discovery |
RogueRobin gathers BIOS versions and manufacturers, the number of CPU cores, the total physical memory, and the computer name. |
| T1102.002 Bidirectional Communication |
RogueRobin has used Google Drive as a Command and Control channel. |
| T1105 Ingress Tool Transfer |
RogueRobin can save a new file to the system from the C2 server. |
| T1113 Screen Capture |
RogueRobin has a command named |
| T1132.001 Standard Encoding |
RogueRobin base64 encodes strings that are sent to the C2 over its DNS tunnel. |
| T1140 Deobfuscate/Decode Files or Information |
RogueRobin decodes an embedded executable using base64 and decompresses it. |
| T1218.010 Regsvr32 |
RogueRobin uses regsvr32.exe to run a .sct file for execution. |
| T1497.001 System Checks |
RogueRobin uses WMI to check BIOS version for VBOX, bochs, qemu, virtualbox, and vm to check for evidence that the script might be executing within an analysis environment. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.