forked from magicsword-io/LOLRMM
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathatera.yaml
221 lines (221 loc) · 7.43 KB
/
atera.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
Name: Atera
Description: |
Atera is a remote monitoring and management (RMM) tool. It is used by threat actors to deploy ransomware or facilitate command execution and lateral movement.
Created: '2024-08-03'
LastModified: '2024-10-06'
Details:
Website: https://www.atera.com/
PEMetadata:
- Filename: AteraAgent.exe
OriginalFileName: AteraAgent.exe
Description: AteraAgent
Privileges: SYSTEM
Free: 30 day trial
Verification: None
SupportedOS:
- Windows
- MacOS
- Linux
Capabilities:
- Integrated remote access with Splashtop and AnyDesk
- Remote monitoring and management
- Patch management
- Network discovery
- Backup and disaster recovery
- Helpdesk and ticketing
- Reporting and analytics
- Billing and invoicing
- Customer portal
- Mobile app
Vulnerabilities:
- CVE-2023-26078
- CVE-2023-26077
InstallationPaths:
- '*\AgentPackageNetworkDiscovery.exe'
- '*\AgentPackageTaskScheduler.exe'
- '*\ATERA Networks\AteraAgent\*'
- '*\AteraAgent.exe'
- atera_agent.exe
- atera_agent.exe
- ateraagent.exe
- C:\Program Files\ATERA Networks\AteraAgent\*
- C:\Program Files\Atera Networks
- C:\Program Files (x86)\Atera Networks
- syncrosetup.exe
Artifacts:
Disk:
- File: C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageRunCommandInteractive\log.txt
Description: N/A
OS: Windows
- File: C:\Program Files\ATERA Networks\AteraAgent\Packages\*
Description: N/A
OS: Windows
- File: C:\Program Files\ATERA Networks\AteraAgent\AteraAgent.exe
Description: Atera service binary
OS: Windows
- File: C:\Program Files\Atera Networks\AlphaAgent.exe
Description: Atera service binary
OS: Windows
- File: C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exe
Description: N/A
OS: Windows
- File: C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe
Description: N/A
OS: Windows
- File: C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageHeartbeat\AgentPackageHeartbeat.exe
Description: N/A
OS: Windows
- File: C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageFileExplorer\AgentPackageFileExplorer.exe
Description: N/A
OS: Windows
- File: C:\Program Files\ATERA Networks\AteraAgent\Packages\AgentPackageRunCommandInteractive\AgentPackageRunCommandInteractive.exe
Description: N/A
OS: Windows
EventLog:
- EventID: 7045
ProviderName: Service Control Manager
LogFile: System.evtx
ServiceName: AteraAgent
ImagePath: '"C:\\Program Files (x86)\\ATERA Networks\\AteraAgent\\AteraAgent.exe"'
Description: Service installation event as result of AteraAgent installation.
- EventID: 7045
ProviderName: Service Control Manager
LogFile: System.evtx
ServiceName: WinRing0_1_2_0
ImagePath: '"C:\\Program Files (x86)\\ATERA Networks\\AteraAgent\\Packages\\AgentPackageMonitoring\\OpenHardwareMonitorLib.sys"'
Description: Service installation event as result of Atera pakcage manager installation.
- EventID: 11707
ProviderName: MsiInstaller
LogFile: Application.evtx
Data: 'Product: AteraAgent -- Installation completed successfully.'
Description: Service installation event as result of AteraAgent installation.
- EventID: 4697
ProviderName: Microsoft-Security-Auditing
LogFile: Security.evtx
CommandLine: C:\\Program Files\\ATERA Networks\\AteraAgent\\Packages\\AgentPackageFileExplorer\\AgentPackageFileExplorer.exe
XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXX XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXX agent-api.atera.com/Production
443 [BASE64BLOB]
Description: Service installation event as result of AteraAgent installation.
Registry:
- Path: HKLM\SOFTWARE\ATERA Networks\AlphaAgent
Description: null
- Path: HKLM\SYSTEM\CurrentControlSet\Services\AteraAgent
Description: null
- Path: KLM\SOFTWARE\WOW6432Node\Splashtop Inc.
Description: null
- Path: HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Splashtop
Software Updater
Description: null
- Path: HKLM\SYSTEM\ControlSet\Services\EventLog\Application\AlphaAgent
Description: null
- Path: HKLM\SYSTEM\ControlSet\Services\EventLog\Application\AteraAgent
Description: null
- Path: HKLM\SOFTWARE\Microsoft\Tracing\AteraAgent_RASAPI32
Description: null
- Path: HKLM\SOFTWARE\Microsoft\Tracing\AteraAgent_RASMANCS
Description: null
- Path: HKLM\SOFTWARE\ATERA Networks\*
Description: null
Network:
- Description: N/A
Domains:
- pubsub.atera.com
Ports:
- N/A
- Description: N/A
Domains:
- pubsub.pubnub.com
Ports:
- N/A
- Description: N/A
Domains:
- agentreporting.atera.com
Ports:
- N/A
- Description: N/A
Domains:
- getalphacontrol.com
Ports:
- N/A
- Description: N/A
Domains:
- app.atera.com
Ports:
- N/A
- Description: N/A
Domains:
- agenthb.atera.com
Ports:
- N/A
- Description: N/A
Domains:
- packagesstore.blob.core.windows.net
Ports:
- N/A
- Description: N/A
Domains:
- ps.pndsn.com
Ports:
- N/A
- Description: N/A
Domains:
- agent-api.atera.com
Ports:
- N/A
- Description: N/A
Domains:
- cacerts.thawte.com
Ports:
- N/A
- Description: N/A
Domains:
- agentreportingstore.blob.core.windows.net
Ports:
- N/A
- Description: N/A
Domains:
- atera-agent-heartbeat.servicebus.windows.net
Ports:
- N/A
- Description: N/A
Domains:
- ps.atera.com
Ports:
- N/A
- Description: N/A
Domains:
- atera.pubnubapi.com
Ports:
- N/A
- Description: N/A
Domains:
- appcdn.atera.com
Ports:
- N/A
Detections:
- Sigma: https://github.com/The-DFIR-Report/Sigma-Rules/blob/d67407d357ad32b247e2a303abc5a38bb30fd576/rules/windows/process_creation/proc_creation_win_ateraagent_malicious_installations.yml
Name: AteraAgent malicious installations
Description: Detects AteraAgent installations with suspicious command line arguments.
- Sigma: https://github.com/SigmaHQ/sigma/blob/782f0f524e6f797ea114fe0d87b22cb4abaa6b7c/rules/windows/builtin/application/msiinstaller/win_software_atera_rmm_agent_install.yml
Name: Atera Agent Installation
Description: Detects Atera Agent installation.
- Sigma: https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/atera_registry_sigma.yml
Description: Detects potential registry activity of Atera RMM tool
- Sigma: https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/atera_network_sigma.yml
Description: Detects potential network activity of Atera RMM tool
- Sigma: https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/atera_files_sigma.yml
Description: Detects potential files activity of Atera RMM tool
- Sigma: https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/atera_processes_sigma.yml
Description: Detects potential processes activity of Atera RMM tool
References:
- https://support.atera.com/hc/en-us/articles/360015461139-Firewall-Settings-for-Atera-s-Integrations
- https://support.atera.com/hc/en-us/articles/215955967-Troubleshoot-Atera-s-Windows-agent
- https://support.atera.com/hc/en-us/articles/115015619747-Release-Notes-February-2018
- https://thedfirreport.com/?s=ateraagent
Acknowledgement:
- Person: "Th\xE9o Letailleur"
Handle: in/theosyn
- Person: Nasreddine Bencherchali
Handle: '@nas_bench'
- Person: Kostas
Handle: '@kostastsale'