Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
CORALDECK has exfiltrated data in HTTP POST headers. |
| T1083 File and Directory Discovery |
CORALDECK searches for specified files. |
| T1560.001 Archive via Utility |
CORALDECK has created password-protected RAR, WinImage, and zip archives to be exfiltrated. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.