PcShare

S1050

Tool.View on attack.mitre.org

About this tool

PcShare is an open source remote access tool that has been modified and used by Chinese threat actors, most notably during the FunnyDream campaign since late 2018.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1005
Data from Local System

PcShare can collect files and information from a compromised host.

T1012
Query Registry

PcShare can search the registry files of a compromised host.

T1016
System Network Configuration Discovery

PcShare can obtain the proxy settings of a compromised machine using `InternetQueryOptionA` and its IP address by running `nslookup myip.opendns.comresolver1.opendns.com\r\n`.

T1027.013
Encrypted/Encoded File

PcShare has been encrypted with XOR using different 32-long Base16 strings.

T1027.015
Compression

PcShare has been compressed with LZW algorithm.

T1036.001
Invalid Code Signature

PcShare has used an invalid certificate in attempt to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location

PcShare has been named `wuauclt.exe` to appear as the legitimate Windows Update AutoUpdate Client.

T1041
Exfiltration Over C2 Channel

PcShare can upload files and information from a compromised host to its C2 servers.

T1055
Process Injection

The PcShare payload has been injected into the `logagent.exe` and `rdpclip.exe` processes.

T1056.001
Keylogging

PcShare has the ability to capture keystrokes.

T1057
Process Discovery

PcShare can obtain a list of running processes on a compromised host.

T1059.003
Windows Command Shell

PcShare can execute `cmd` commands on a compromised host.

T1070.004
File Deletion

PcShare has deleted its files and components from a compromised host.

T1071.001
Web Protocols

PcShare has used HTTP for C2 communication.

T1106
Native API

PcShare has used a variety of Windows API functions.

View all 21 procedure examples

Groups that use it1

Campaigns1

References2

  1. Bitdefender FunnyDream Campaign November 2020 Open source
    Vrabie, V. (2020, November). Dissecting a Chinese APT Targeting South Eastern Asian Government Institutions. Retrieved September 19, 2022.
  2. GitHub PcShare 2014 Open source
    LiveMirror. (2014, September 17). PcShare. Retrieved October 11, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.