Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
Remsec can dump the SAM database. |
| T1016 System Network Configuration Discovery |
Remsec can obtain information about network configuration, including the routing table, ARP cache, and DNS cache. |
| T1018 Remote System Discovery |
Remsec can ping or traceroute a remote host. |
| T1025 Data from Removable Media |
Remsec has a package that collects documents from any inserted USB sticks. |
| T1027.013 Encrypted/Encoded File |
Some data in Remsec is encrypted using RC5 in CBC mode, AES-CBC with a hardcoded key, RC4, or Salsa20. Some data is also base64-encoded. |
| T1033 System Owner/User Discovery |
Remsec can obtain information about the current user. |
| T1036.005 Match Legitimate Resource Name or Location |
The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims. |
| T1046 Network Service Discovery |
Remsec has a plugin that can perform ARP scanning as well as port scanning. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel. |
| T1049 System Network Connections Discovery |
Remsec can obtain a list of active connections and open ports. |
| T1052.001 Exfiltration over USB |
Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device. |
| T1053.005 Scheduled Task |
Remsec schedules the execution one of its modules by creating a new scheduler task. |
| T1055.001 Dynamic-link Library Injection |
Remsec can perform DLL injection. |
| T1056.001 Keylogging |
Remsec contains a keylogger component. |
| T1057 Process Discovery |
Remsec can obtain a process list from the victim. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.