Malware.View on attack.mitre.org
DownPaper is a backdoor Trojan; its main functionality is to download and run second stage malware.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
DownPaper searches and reads the value of the Windows Update Registry Run key. |
| T1033 System Owner/User Discovery |
DownPaper collects the victim username and sends it to the C2 server. |
| T1059.001 PowerShell |
DownPaper uses PowerShell for execution. |
| T1059.003 Windows Command Shell |
DownPaper uses the command line. |
| T1071.001 Web Protocols |
DownPaper communicates to its C2 server over HTTP. |
| T1082 System Information Discovery |
DownPaper collects the victim host name and serial number, and then sends the information to the C2 server. |
| T1547.001 Registry Run Keys / Startup Folder |
DownPaper uses PowerShell to add a Registry Run key in order to establish persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.