S-Type is a backdoor that was used by Dust Storm from 2013 to 2014. [1]
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1087 | .001 | Account Discovery: Local Account |
S-Type runs the command |
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols | |
Enterprise | T1547 | .001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
S-Type may create a .lnk file to itself that is saved in the Start menu folder. It may also create the Registry key |
.009 | Boot or Logon Autostart Execution: Shortcut Modification |
S-Type may create the file |
||
Enterprise | T1136 | .001 | Create Account: Local Account |
S-Type may create a temporary user on the system named "Lost_{{Unique Identifier}}" with the password "pond~!@6"{{Unique Identifier}}."[1] |
Enterprise | T1132 | .001 | Data Encoding: Standard Encoding | |
Enterprise | T1008 | Fallback Channels |
S-Type primarily uses port 80 for C2, but falls back to ports 443 or 8080 if initial communication fails.[1] |
|
Enterprise | T1036 | .005 | Masquerading: Match Legitimate Name or Location |
S-Type may save itself as a file named msdtc.exe, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.[1][2] |
Enterprise | T1082 | System Information Discovery |
The initial beacon packet for S-Type contains the operating system version and file system of the victim.[1] |
|
Enterprise | T1007 | System Service Discovery |
ID | Name | References |
---|---|---|
G0031 | Dust Storm |