Malware.View on attack.mitre.org
SampleCheck5000 is a downloader with multiple variants that was used by OilRig including during the Outer Space campaign to download and execute additional payloads.
| Technique | Procedure example |
|---|---|
| T1059.003 Windows Command Shell |
SampleCheck5000 can call cmd.exe to execute C2 command line strings. |
| T1071.001 Web Protocols |
SampleCheck5000 can use the Exchange Web Services API for C2 communication. |
| T1074.001 Local Data Staging |
SampleCheck5000 can log the output from C2 commands in an encrypted and compressed format on disk prior to exfiltration. |
| T1082 System Information Discovery |
SampleCheck5000 can create unique victim identifiers by using the compromised system’s computer name. |
| T1102.002 Bidirectional Communication |
SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve C2 commands and payloads placed in Draft messages. |
| T1105 Ingress Tool Transfer |
SampleCheck5000 can download additional payloads to compromised hosts. |
| T1140 Deobfuscate/Decode Files or Information |
SampleCheck5000 can decode and decrypt command line strings and files received through C2. |
| T1560.001 Archive via Utility |
SampleCheck5000 can gzip compress files uploaded to a shared mailbox used for C2 and exfiltration. |
| T1567 Exfiltration Over Web Service |
SampleCheck5000 can use the Microsoft Office Exchange Web Services API to access an actor-controlled account and retrieve files for exfiltration. |
| T1680 Local Storage Discovery |
SampleCheck5000 can create unique victim identifiers by using the compromised system’s volume ID. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.