THREAT OPS › Threat News › PEEP: A Browser RAT Posing as a Chrome Extension
PEEP: A Browser RAT Posing as a Chrome Extension
<h1>PEEP: A Browser RAT Posing as a Chrome Extension</h1> <p>The Threat Research Unit (STRU) at SOCRadar’s <a href="https://socradar.io/products/extended-threat-intelligence/?utm_campaign=blogpage&utm_source=website&utm_medium=blog&utm_term=extendedthreatintelligence&utm_content=blogxti">Extended Threat Intelligence (XTI)</a> platform identified and analyzed <strong>PEEP</strong>,
Attributed threat actors
- Earth LuscaG1006
MITRE ATT&CK techniques
- Screen CaptureT1113
- Acquire InfrastructureT1583
- IP AddressesT1590.005
- JavaScriptT1059.007
- Steal Web Session CookieT1539
- MalwareT1587.001
- Browser ExtensionsT1176.001
- Automated CollectionT1119
- Clipboard DataT1115
- System Service DiscoveryT1007
- Application Layer ProtocolT1071
- Software ExtensionsT1176
- Data from Local SystemT1005
- Remote Access ToolsT1219
- MasqueradingT1036
- Control PanelT1218.002
- Modify RegistryT1112
- Browser Information DiscoveryT1217
- Private KeysT1552.004
- Web Portal CaptureT1056.003
- ProxyT1090
- Command and Scripting InterpreterT1059
- File and Directory DiscoveryT1083
- Web ServicesT1583.006
- Process DiscoveryT1057
- Exfiltration Over C2 ChannelT1041
- PowerShellT1059.001
- Web ServicesT1584.006
- Non-Standard PortT1571
- Obfuscated Files or InformationT1027
- Subvert Trust ControlsT1553
- Input CaptureT1056
- CredentialsT1589.001
- Web Session CookieT1550.004
- Windows Command ShellT1059.003
- Web ProtocolsT1071.001
- Software DiscoveryT1518
- Ingress Tool TransferT1105
- Develop CapabilitiesT1587
- Acquire InfrastructureAML.T0008
- Develop CapabilitiesAML.T0017
- Data from Local SystemAML.T0037
- Command and Scripting InterpreterAML.T0050
- MasqueradingAML.T0074
- Process DiscoveryAML.T0089
Indicators of compromise
- 86a5fb2f14d175d1c13a7b49b55b968b2a5e96afc944d85a31b3db906af00bebsha256
- 6700e30a3224248085d30f2eb727cea28dec288355fca6753449a26d1c1d1eeesha256
- 9402c0198ae5c8bed14cdeaabe7e8b25625debbc62a900cfcdb82d34a35ab528sha256
- 8edd653910f3217c96a603e8ce9e5e409d3b8674476f22e0a3afe870bf3870b1sha256
- 87db7138a80117ddf2989827c1dde09ee73c7a252d511c74ed66af2fe34e2987sha256
- 259d8eddb6caf509d7bffa2b4c0dd7d89668800c870f529729ac2efdc1853fb6sha256
- e46aee4ca43ba66666f6572c62365cf57642f2cf1f6eca00fcf8eb33a291d66dsha256
- f031c00f592aa5e98893b4532f743362fed7fb0a485e8a3c0ad4de677f1d7415sha256
- a43bf7f81507c8f9d0942fed331e7590a43044a6d219ec1005974bf1a81974a1sha256
- b4e3ca8f44477b9ade1272f92516202f83a80219c8bd6176527a6d624214e893sha256
- 8e988b915b75dd749e3f4e1ca7ee21746885b4fe34e8a246e6f10f5d892a675fsha256
- 9c6b269e5087a40b4552f72e9ff13d9b39e433af5075ad68f57e9b5240a590d8sha256
- 207e0d47c4e5493ef7313eb1faeb1c6195923c89f263e548609a6838dd91ec0csha256
- 206.237.30.232ipv4
- api.ipify.orgdomain
- ifconfig.medomain
- icanhazip.comdomain
Original source: https://socradar.io/blog/peep-browser-rat-chrome-extension/