ATT&CKReferencesTrusteer Carberp October 2010

Trusteer Carberp October 2010

Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareCarberp

Carberp has masqueraded as Windows system file names, as well as "chkntfs.exe" and "syscron.exe".

T1041
Exfiltration Over C2 Channel
MalwareCarberp

Carberp has exfiltrated data via HTTP to already established C2 servers.

T1057
Process Discovery
MalwareCarberp

Carberp has collected a list of running processes.

T1071.001
Web Protocols
MalwareCarberp

Carberp has connected to C2 servers via HTTP.

T1105
Ingress Tool Transfer
MalwareCarberp

Carberp can download and execute new plugins from the C2 server.

T1106
Native API
MalwareCarberp

Carberp has used the NtQueryDirectoryFile and ZwQueryDirectoryFile functions to hide files and directories.

T1185
Browser Session Hijacking
MalwareCarberp

Carberp has captured credentials when a user performs login through a SSL session.

T1564.001
Hidden Files and Directories
MalwareCarberp

Carberp has created a hidden file in the Startup folder of the current user.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.