Putter Panda
Associated Group Descriptions |
|
Name | Description |
---|---|
MSUpdater | (Citation: CrowdStrike Putter Panda) |
APT2 | (Citation: Cylance Putter Panda) |
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1547 | .001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
A dropper used by Putter Panda installs itself into the ASEP Registry key |
Enterprise | T1562 | .001 | Impair Defenses: Disable or Modify Tools |
Malware used by Putter Panda attempts to terminate processes corresponding to two components of Sophos Anti-Virus (SAVAdminService.exe and SavService.exe).(Citation: CrowdStrike Putter Panda) |
Enterprise | T1027 | .013 | Obfuscated Files or Information: Encrypted/Encoded File |
Droppers used by Putter Panda use RC4 or a 16-byte XOR key consisting of the bytes 0xA0 – 0xAF to obfuscate payloads.(Citation: CrowdStrike Putter Panda) |
Enterprise | T1055 | .001 | Process Injection: Dynamic-link Library Injection |
An executable dropped onto victims by Putter Panda aims to inject the specified DLL into a process that would normally be accessing the network, including Outlook Express (msinm.exe), Outlook (outlook.exe), Internet Explorer (iexplore.exe), and Firefox (firefox.exe).(Citation: CrowdStrike Putter Panda) |
Software |
|||
ID | Name | References | Techniques |
---|---|---|---|
S0066 | 3PARA RAT | (Citation: CrowdStrike Putter Panda) | Symmetric Cryptography, Web Protocols, File and Directory Discovery, Timestomp |
S0067 | pngdowner | (Citation: CrowdStrike Putter Panda) | Web Protocols, File Deletion, Credentials In Files |
S0065 | 4H RAT | (Citation: CrowdStrike Putter Panda) | File and Directory Discovery, System Information Discovery, Windows Command Shell, Web Protocols, Symmetric Cryptography, Process Discovery |
S0068 | httpclient | (Citation: CrowdStrike Putter Panda) | Symmetric Cryptography, Web Protocols, Windows Command Shell |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.