Lelli, A. (2010, January 11). Trojan.Hydraq. Retrieved February 20, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can read data from files. |
| T1007 System Service Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can monitor services. |
| T1012 Query Registry |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can retrieve system information, such as CPU speed, from Registry keys. |
| T1016 System Network Configuration Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can retrieve IP addresses of compromised machines. |
| T1048 Exfiltration Over Alternative Protocol |
MalwareHydraq | Hydraq connects to a predefined domain on port 443 to exfil gathered information. |
| T1057 Process Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can monitor processes. |
| T1070.004 File Deletion |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can delete files. |
| T1082 System Information Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can retrieve information such as computer name, OS version, processor speed, memory size, and CPU speed. |
| T1083 File and Directory Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can check for the existence of files, including its own components, as well as retrieve a list of logical drives. |
| T1105 Ingress Tool Transfer |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can download files and additional malware components. |
| T1112 Modify Registry |
MalwareHydraq | Hydraq creates a Registry subkey to register its created service, and can also uninstall itself later by deleting this value. Hydraq's backdoor also enables remote attackers to modify and delete subkeys. |
| T1113 Screen Capture |
MalwareHydraq | Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop of an infected host. |
| T1129 Shared Modules |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can load and call DLL functions. |
| T1134 Access Token Manipulation |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can adjust token privileges. |
| T1543.003 Windows Service |
MalwareHydraq | Hydraq creates new services to establish persistence. |
| T1573.001 Symmetric Cryptography |
MalwareHydraq | Hydraq C2 traffic is encrypted using bitwise NOT and XOR operations. |
| T1685.005 Clear Windows Event Logs |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can clear all system event logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.