SHOTPUT is a custom backdoor used by APT3. [1]

ID: S0063
Associated Software: Backdoor.APT.CookieCutter, Pirpi
Platforms: Windows
Version: 1.1
Created: 31 May 2017
Last Modified: 30 March 2020

Techniques Used

Domain ID Name Use
Enterprise T1087 .001 Account Discovery: Local Account

SHOTPUT has a command to retrieve information about connected users.[3]

Enterprise T1083 File and Directory Discovery

SHOTPUT has a command to obtain a directory listing.[3]

Enterprise T1027 Obfuscated Files or Information

SHOTPUT is obscured using XOR encoding and appended to a valid GIF file.[1][3]

Enterprise T1057 Process Discovery

SHOTPUT has a command to obtain a process listing.[3]

Enterprise T1018 Remote System Discovery

SHOTPUT has a command to list all servers in the domain, as well as one to locate domain controllers on a domain.[3]

Enterprise T1049 System Network Connections Discovery

SHOTPUT uses netstat to list TCP connection status.[3]

Groups That Use This Software

ID Name References
G0022 APT3