Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1052.001 Exfiltration over USB |
SPACESHIP copies staged data to removable drives when they are inserted into the system. |
| T1074.001 Local Data Staging |
SPACESHIP identifies files with certain extensions and copies them to a directory in the user's profile. |
| T1083 File and Directory Discovery |
SPACESHIP identifies files and directories for collection by searching for specific file extensions or file modification time. |
| T1547.001 Registry Run Keys / Startup Folder |
SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder. |
| T1547.009 Shortcut Modification |
SPACESHIP achieves persistence by creating a shortcut in the current user's Startup folder. |
| T1560.003 Archive via Custom Method |
Data SPACESHIP copies to the staging area is compressed with zlib. Bytes are rotated by four positions and XOR'ed with 0x23. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.