ATT&CKSoftwareSampleCheck5000

SampleCheck5000

S1168

Malware.View on attack.mitre.org

About this malware

SampleCheck5000 is a downloader with multiple variants that was used by OilRig including during the Outer Space campaign to download and execute additional payloads.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1059.003
Windows Command Shell

SampleCheck5000 can call cmd.exe to execute C2 command line strings.

T1071.001
Web Protocols

SampleCheck5000 can use the Exchange Web Services API for C2 communication.

T1074.001
Local Data Staging

SampleCheck5000 can log the output from C2 commands in an encrypted and compressed format on disk prior to exfiltration.

T1082
System Information Discovery

SampleCheck5000 can create unique victim identifiers by using the compromised system’s computer name.

T1102.002
Bidirectional Communication

SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages.

T1105
Ingress Tool Transfer

SampleCheck5000 can download additional payloads to compromised hosts.

T1140
Deobfuscate/Decode Files or Information

SampleCheck5000 can decode and decrypt command line strings and files received through C2.

T1560.001
Archive via Utility

SampleCheck5000 can gzip compress files uploaded to a shared mailbox used for C2 and exfiltration.

T1567
Exfiltration Over Web Service

SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration.

T1680
Local Storage Discovery

SampleCheck5000 can create unique victim identifiers by using the compromised system’s volume ID.

Groups that use it1

Campaigns1

References2

  1. ESET OilRig Campaigns Sep 2023 Open source
    Hromcova, Z. and Burgher, A. (2023, September 21). OilRig’s Outer Space and Juicy Mix: Same ol’ rig, new drill pipes. Retrieved November 21, 2024.
  2. ESET OilRig Downloaders DEC 2023 Open source
    Hromcova, Z. and Burgher, A. (2023, December 14). OilRig’s persistent attacks using cloud service-powered downloaders. Retrieved November 26, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.