Raccoon Stealer
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1087 | .001 | Account Discovery: Local Account |
Raccoon Stealer checks the privileges of running processes to determine if the running user is equivalent to `NT Authority\System`.(Citation: Sekoia Raccoon2 2022) |
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols |
Raccoon Stealer uses HTTP, and particularly HTTP POST requests, for command and control actions.(Citation: S2W Racoon 2022)(Citation: Sekoia Raccoon1 2022)(Citation: Sekoia Raccoon2 2022) |
Enterprise | T1555 | .003 | Credentials from Password Stores: Credentials from Web Browsers |
Raccoon Stealer collects passwords, cookies, and autocomplete information from various popular web browsers.(Citation: Sekoia Raccoon2 2022) |
Enterprise | T1070 | .004 | Indicator Removal: File Deletion |
Raccoon Stealer can remove files related to use and installation.(Citation: Sekoia Raccoon1 2022) |
Enterprise | T1027 | .007 | Obfuscated Files or Information: Dynamic API Resolution |
Raccoon Stealer dynamically links key WinApi functions during execution.(Citation: Sekoia Raccoon1 2022)(Citation: Sekoia Raccoon2 2022) |
.013 | Obfuscated Files or Information: Encrypted/Encoded File |
Raccoon Stealer uses RC4 encryption for strings and command and control addresses to evade static detection.(Citation: S2W Racoon 2022)(Citation: Sekoia Raccoon1 2022)(Citation: Sekoia Raccoon2 2022) |
References
- Quentin Bourgue, Pierre le Bourhis, & Sekoia TDR. (2022, June 28). Raccoon Stealer v2 - Part 1: The return of the dead. Retrieved August 1, 2024.
- S2W TALON. (2022, June 16). Raccoon Stealer is Back with a New Version. Retrieved August 1, 2024.
- Pierre Le Bourhis, Quentin Bourgue, & Sekoia TDR. (2022, June 29). Raccoon Stealer v2 - Part 2: In-depth analysis. Retrieved August 1, 2024.
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.