Burton, K. (n.d.). The Conficker Worm. Retrieved February 18, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.002 SMB/Windows Admin Shares |
MalwareConficker | Conficker variants spread through NetBIOS share propagation. |
| T1046 Network Service Discovery |
MalwareConficker | Conficker scans for other machines to infect. |
| T1091 Replication Through Removable Media |
MalwareConficker | Conficker variants used the Windows AUTORUN feature to spread through USB propagation. |
| T1105 Ingress Tool Transfer |
MalwareConficker | Conficker downloads an HTTP server to the infected machine. |
| T1112 Modify Registry |
MalwareConficker | Conficker adds keys to the Registry at |
| T1124 System Time Discovery |
MalwareConficker | Conficker uses the current UTC victim system date for domain generation and connects to time servers to determine the current date. |
| T1210 Exploitation of Remote Services |
MalwareConficker | Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request. |
| T1490 Inhibit System Recovery |
MalwareConficker | Conficker resets system restore points and deletes backup files. |
| T1543.003 Windows Service |
MalwareConficker | Conficker copies itself into the |
| T1568.002 Domain Generation Algorithms |
MalwareConficker | Conficker has used a DGA that seeds with the current UTC victim system date to generate domains. |
| T1685 Disable or Modify Tools |
MalwareConficker | Conficker terminates various services related to system security and Windows. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.