SQLRat

S0390

Malware.View on attack.mitre.org

About this malware

SQLRat is malware that executes SQL scripts to avoid leaving traditional host artifacts. FIN7 has been observed using it.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.010
Command Obfuscation

SQLRat has used a character insertion obfuscation technique, making the script appear to contain Chinese characters.

T1053.005
Scheduled Task

SQLRat has created scheduled tasks in %appdata%\Roaming\Microsoft\Templates\.

T1059.001
PowerShell

SQLRat has used PowerShell to create a Meterpreter session.

T1059.003
Windows Command Shell

SQLRat has used SQL to execute JavaScript and VB scripts on the host system.

T1070.004
File Deletion

SQLRat has used been observed deleting scripts once used.

T1105
Ingress Tool Transfer

SQLRat can make a direct SQL connection to a Microsoft database controlled by the attackers, retrieve an item from the bindata table, then write and execute the file on disk.

T1140
Deobfuscate/Decode Files or Information

SQLRat has scripts that are responsible for deobfuscating additional scripts.

T1204.002
Malicious File

SQLRat relies on users clicking on an embedded image to execute the scripts.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Flashpoint FIN 7 March 2019 Open source
    Platt, J. and Reeves, J.. (2019, March). FIN7 Revisited: Inside Astra Panel and SQLRat Malware. Retrieved June 18, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.