Trend Micro. (2014, March 18). Conficker. Retrieved February 18, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareConficker | Conficker has obfuscated its code to prevent its removal from host machines. |
| T1091 Replication Through Removable Media |
MalwareConficker | Conficker variants used the Windows AUTORUN feature to spread through USB propagation. |
| T1112 Modify Registry |
MalwareConficker | Conficker adds keys to the Registry at |
| T1124 System Time Discovery |
MalwareConficker | Conficker uses the current UTC victim system date for domain generation and connects to time servers to determine the current date. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareConficker | Conficker adds Registry Run keys to establish persistence. |
| T1568.002 Domain Generation Algorithms |
MalwareConficker | Conficker has used a DGA that seeds with the current UTC victim system date to generate domains. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.