Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
The C2 server used by XTunnel provides a port number to the victim to use as a fallback in case the connection closes on the currently used port. |
| T1027 Obfuscated Files or Information |
A version of XTunnel introduced in July 2015 obfuscated the binary using opaque predicates and other techniques in a likely attempt to obfuscate it and bypass security products. |
| T1027.016 Junk Code Insertion |
A version of XTunnel introduced in July 2015 inserted junk code into the binary in a likely attempt to obfuscate it and bypass security products. |
| T1046 Network Service Discovery |
XTunnel is capable of probing the network for open ports. |
| T1059.003 Windows Command Shell |
XTunnel has been used to execute remote commands. |
| T1090 Proxy |
XTunnel relays traffic between a C2 server and a victim. |
| T1552.001 Credentials In Files |
XTunnel is capable of accessing locally stored passwords on victims. |
| T1573.002 Asymmetric Cryptography |
XTunnel uses SSL/TLS and RC4 to encrypt traffic. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.