Adamitis, D. (2020, May 6). Phantom in the Command Shell. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareEVILNUM | EVILNUM can obtain the username from the victim's machine. |
| T1041 Exfiltration Over C2 Channel |
MalwareEVILNUM | EVILNUM can upload files over the C2 channel from the infected host. |
| T1047 Windows Management Instrumentation |
MalwareEVILNUM | EVILNUM has used the Windows Management Instrumentation (WMI) tool to enumerate infected machines. |
| T1070 Indicator Removal |
MalwareEVILNUM | EVILNUM has a function called "DeleteLeftovers" to remove certain artifacts of the attack. |
| T1070.006 Timestomp |
MalwareEVILNUM | EVILNUM has changed the creation date of files. |
| T1082 System Information Discovery |
MalwareEVILNUM | EVILNUM can obtain the computer name from the victim's system. |
| T1102.003 One-Way Communication |
MalwareEVILNUM | EVILNUM has used a one-way communication method via GitLab and Digital Point to perform C2. |
| T1105 Ingress Tool Transfer |
MalwareEVILNUM | EVILNUM can download and upload files to the victim's computer. |
| T1112 Modify Registry |
MalwareEVILNUM | EVILNUM can make modifications to the Regsitry for persistence. |
| T1218.011 Rundll32 |
MalwareEVILNUM | EVILNUM can execute commands and scripts through rundll32. |
| T1518.001 Security Software Discovery |
MalwareEVILNUM | EVILNUM can search for anti-virus products on the system. |
| T1539 Steal Web Session Cookie |
MalwareEVILNUM | EVILNUM can harvest cookies and upload them to the C2 server. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareEVILNUM | EVILNUM can achieve persistence through the Registry Run key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.