Sebastian Feldmann. (2018, February 14). Chaos: a Stolen Backdoor Rising Again. Retrieved March 5, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.004 Unix Shell |
MalwareChaos | Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES. |
| T1104 Multi-Stage Channels |
MalwareChaos | After initial compromise, Chaos will download a second stage to establish a more permanent presence on the affected system. |
| T1110 Brute Force |
MalwareChaos | Chaos conducts brute force attacks against SSH services to gain initial access. |
| T1205 Traffic Signaling |
MalwareChaos | Chaos provides a reverse shell is triggered upon receipt of a packet with a special string, sent to any port. |
| T1573.001 Symmetric Cryptography |
MalwareChaos | Chaos provides a reverse shell connection on 8338/TCP, encrypted via AES. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.