Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
Hi-Zor uses various XOR techniques to obfuscate its components. |
| T1059.003 Windows Command Shell |
Hi-Zor has the ability to create a reverse shell. |
| T1070.004 File Deletion |
Hi-Zor deletes its RAT installer file as it executes its DLL payload file. |
| T1071.001 Web Protocols |
Hi-Zor communicates with its C2 server over HTTPS. |
| T1105 Ingress Tool Transfer |
Hi-Zor has the ability to upload and download files from its C2 server. |
| T1218.010 Regsvr32 |
Hi-Zor executes using regsvr32.exe called from the Registry Run Keys / Startup Folder persistence mechanism. |
| T1547.001 Registry Run Keys / Startup Folder |
Hi-Zor creates a Registry Run key to establish persistence. |
| T1573.001 Symmetric Cryptography |
Hi-Zor encrypts C2 traffic with a double XOR using two distinct single-byte keys. |
| T1573.002 Asymmetric Cryptography |
Hi-Zor encrypts C2 traffic with TLS. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.