Threat Intelligence and Research. (2015, March 30). VOLATILE CEDAR. Retrieved February 8, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareExplosive | Explosive has collected the MAC address from the victim's machine. |
| T1025 Data from Removable Media |
MalwareExplosive | Explosive can scan all .exe files located in the USB drive. |
| T1033 System Owner/User Discovery |
MalwareExplosive | Explosive has collected the username from the infected host. |
| T1056.001 Keylogging |
MalwareExplosive | Explosive has leveraged its keylogging capabilities to gain access to administrator accounts on target servers. |
| T1071.001 Web Protocols |
MalwareExplosive | Explosive has used HTTP for communication. |
| T1082 System Information Discovery |
MalwareExplosive | Explosive has collected the computer name from the infected host. |
| T1105 Ingress Tool Transfer |
MalwareExplosive | Explosive has a function to download a file to the infected system. |
| T1106 Native API |
MalwareExplosive | Explosive has a function to call the OpenClipboard wrapper. |
| T1112 Modify Registry |
MalwareExplosive | Explosive has a function to write itself to Registry values. |
| T1115 Clipboard Data |
MalwareExplosive | Explosive has a function to use the OpenClipboard wrapper. |
| T1190 Exploit Public-Facing Application |
GroupVolatile Cedar | Volatile Cedar has targeted publicly facing web servers, with both automatic and manual vulnerability discovery. |
| T1505.003 Web Shell |
GroupVolatile Cedar | Volatile Cedar can inject web shell code into a server. |
| T1564.001 Hidden Files and Directories |
MalwareExplosive | Explosive has commonly set file and path attributes to hidden. |
| T1595.002 Vulnerability Scanning |
GroupVolatile Cedar | Volatile Cedar has performed vulnerability scans of the target server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.