Rifdoor is a remote access trojan (RAT) that shares numerous code similarities with HotCroissant.[1]
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1573 | .001 | 加密通道: Symmetric Cryptography |
Rifdoor has encrypted command and control (C2) communications with a stream cipher.[1] |
| Enterprise | T1547 | .001 | 启动或登录自动启动执行: Registry Run Keys / Startup Folder |
Rifdoor has created a new registry entry at |
| Enterprise | T1027 | .001 | 混淆文件或信息: Binary Padding |
Rifdoor has added four additional bytes of data upon launching, then saved the changed version as |
| .013 | 混淆文件或信息: Encrypted/Encoded File |
Rifdoor has encrypted strings with a single byte XOR algorithm.[1] |
||
| Enterprise | T1204 | .002 | 用户执行: Malicious File |
Rifdoor has been executed from malicious Excel or Word documents containing macros.[1] |
| Enterprise | T1082 | 系统信息发现 |
Rifdoor has the ability to identify the Windows version on the compromised host.[1] |
|
| Enterprise | T1033 | 系统所有者/用户发现 |
Rifdoor has the ability to identify the username on the compromised host.[1] |
|
| Enterprise | T1016 | 系统网络配置发现 |
Rifdoor has the ability to identify the IP address of the compromised host.[1] |
|
| Enterprise | T1566 | .001 | 钓鱼: Spearphishing Attachment |
Rifdoor has been distributed in e-mails with malicious Excel or Word documents.[1] |