Kwampirs
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1087 | .001 | Account Discovery: Local Account |
Kwampirs collects a list of accounts with the command |
Enterprise | T1543 | .003 | Create or Modify System Process: Windows Service |
Kwampirs creates a new service named WmiApSrvEx to establish persistence.(Citation: Symantec Orangeworm April 2018) |
Enterprise | T1036 | .004 | Masquerading: Masquerade Task or Service |
Kwampirs establishes persistence by adding a new service with the display name "WMI Performance Adapter Extension" in an attempt to masquerade as a legitimate WMI service.(Citation: Symantec Orangeworm April 2018) |
Enterprise | T1027 | .001 | Obfuscated Files or Information: Binary Padding |
Before writing to disk, Kwampirs inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections.(Citation: Symantec Orangeworm April 2018) |
Enterprise | T1069 | .001 | Permission Groups Discovery: Local Groups |
Kwampirs collects a list of users belonging to the local users and administrators groups with the commands |
.002 | Permission Groups Discovery: Domain Groups |
Kwampirs collects a list of domain groups with the command |
||
Enterprise | T1021 | .002 | Remote Services: SMB/Windows Admin Shares |
Kwampirs copies itself over network shares to move laterally on a victim network.(Citation: Symantec Orangeworm April 2018) |
Enterprise | T1218 | .011 | System Binary Proxy Execution: Rundll32 |
Kwampirs uses rundll32.exe in a Registry value added to establish persistence.(Citation: Symantec Orangeworm April 2018) |
Groups That Use This Software |
||
ID | Name | References |
---|---|---|
G0071 | Orangeworm |
(Citation: Symantec Orangeworm April 2018) |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.