Malware.View on attack.mitre.org
StreamEx is a malware family that has been used by Deep Panda since at least 2015. In 2016, it was distributed via legitimate compromised Korean websites.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
StreamEx obfuscates some commands by using statically programmed fragments of strings when starting a DLL. It also uses a one-byte xor against 0x91 to encode configuration data. |
| T1057 Process Discovery |
StreamEx has the ability to enumerate processes. |
| T1059.003 Windows Command Shell |
StreamEx has the ability to remotely execute commands. |
| T1082 System Information Discovery |
StreamEx has the ability to enumerate system information. |
| T1083 File and Directory Discovery |
StreamEx has the ability to enumerate drive types. |
| T1112 Modify Registry |
StreamEx has the ability to modify the Registry. |
| T1218.011 Rundll32 |
StreamEx uses rundll32 to call an exported function. |
| T1518.001 Security Software Discovery |
StreamEx has the ability to scan for security tools such as firewalls and antivirus tools. |
| T1543.003 Windows Service |
StreamEx establishes persistence by installing a new service pointing to its DLL and setting the service to auto-start. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.