Pasam

S0208

Malware.View on attack.mitre.org

About this malware

Pasam is a trojan used by Elderwood to open a backdoor on compromised hosts.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1005
Data from Local System

Pasam creates a backdoor through which remote attackers can retrieve files.

T1057
Process Discovery

Pasam creates a backdoor through which remote attackers can retrieve lists of running processes.

T1070.004
File Deletion

Pasam creates a backdoor through which remote attackers can delete files.

T1082
System Information Discovery

Pasam creates a backdoor through which remote attackers can retrieve information like hostname.

T1083
File and Directory Discovery

Pasam creates a backdoor through which remote attackers can retrieve lists of files.

T1105
Ingress Tool Transfer

Pasam creates a backdoor through which remote attackers can upload files.

T1547.008
LSASS Driver

Pasam establishes by infecting the Security Accounts Manager (SAM) DLL to load a malicious DLL dropped to disk.

T1680
Local Storage Discovery

Pasam creates a backdoor through which remote attackers can retrieve information like free disk space.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Symantec Elderwood Sept 2012 Open source
    O'Gorman, G., and McDonald, G.. (2012, September 6). The Elderwood Project. Retrieved November 17, 2024.
  2. Symantec Pasam May 2012 Open source
    Mullaney, C. & Honda, H. (2012, May 4). Trojan.Pasam. Retrieved February 22, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.