Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
SslMM has a hard-coded primary and backup C2 string. |
| T1033 System Owner/User Discovery |
SslMM sends the logged-on username to its hard-coded C2. |
| T1036.005 Match Legitimate Resource Name or Location |
To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1056.001 Keylogging |
SslMM creates a new thread implementing a keylogging facility using Windows Keyboard Accelerators. |
| T1082 System Information Discovery |
SslMM sends information to its hard-coded C2, including OS version, service pack information, processor speed, system name, and OS install date. |
| T1134 Access Token Manipulation |
SslMM contains a feature to manipulate process privileges and tokens. |
| T1547.001 Registry Run Keys / Startup Folder |
To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1547.009 Shortcut Modification |
To establish persistence, SslMM identifies the Start Menu Startup directory and drops a link to its own executable disguised as an “Office Start,” “Yahoo Talk,” “MSN Gaming Z0ne,” or “MSN Talk” shortcut. |
| T1685 Disable or Modify Tools |
SslMM identifies and kills anti-malware processes. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.