Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
SombRAT has collected data and files from a compromised host. |
| T1007 System Service Discovery |
SombRAT can enumerate services on a victim machine. |
| T1027 Obfuscated Files or Information |
SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data. |
| T1033 System Owner/User Discovery |
SombRAT can execute |
| T1036 Masquerading |
SombRAT can use a legitimate process name to hide itself. |
| T1041 Exfiltration Over C2 Channel |
SombRAT has uploaded collected data and files from a compromised host to its C2 server. |
| T1055.001 Dynamic-link Library Injection |
SombRAT can execute |
| T1057 Process Discovery |
SombRAT can use the |
| T1070.004 File Deletion |
SombRAT has the ability to run |
| T1071.004 DNS |
SombRAT can communicate over DNS with the C2 server. |
| T1074.001 Local Data Staging |
SombRAT can store harvested data in a custom database under the %TEMP% directory. |
| T1082 System Information Discovery |
SombRAT can execute |
| T1083 File and Directory Discovery |
SombRAT can execute |
| T1090 Proxy |
SombRAT has the ability to use an embedded SOCKS proxy in C2 communications. |
| T1095 Non-Application Layer Protocol |
SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.