| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1083 | 文件和目录发现 |
RARSTONE obtains installer properties from Uninstall Registry Key entries to obtain information about installed applications and how to uninstall certain applications.[2] |
|
| Enterprise | T1105 | 输入工具传输 |
RARSTONE downloads its backdoor component from a C2 server and loads it directly into memory.[1] |
|
| Enterprise | T1055 | .001 | 进程注入: Dynamic-link Library Injection |
After decrypting itself in memory, RARSTONE downloads a DLL file from its C2 server and loads it in the memory space of a hidden Internet Explorer process. This "downloaded" file is actually not dropped onto the system.[2] |
| Enterprise | T1095 | 非应用层协议 |
RARSTONE uses SSL to encrypt its communication with its C2 server.[1] |
|