Vasport

S0207

Malware.View on attack.mitre.org

About this malware

Vasport is a trojan used by Elderwood to open a backdoor on compromised hosts.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1071.001
Web Protocols

Vasport creates a backdoor by making a connection using a HTTP POST.

T1090
Proxy

Vasport is capable of tunneling though a proxy.

T1105
Ingress Tool Transfer

Vasport can download files.

T1547.001
Registry Run Keys / Startup Folder

Vasport copies itself to disk and creates an associated run key Registry entry to establish.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Symantec Elderwood Sept 2012 Open source
    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.
  2. Symantec Vasport May 2012 Open source
    Zhou, R. (2012, May 15). Backdoor.Vasport. Retrieved February 22, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.