Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Orz can gather victim proxy information. |
| T1027 Obfuscated Files or Information |
Some Orz strings are base64 encoded, such as the embedded DLL known as MockDll. |
| T1055.012 Process Hollowing |
Some Orz versions have an embedded DLL known as MockDll that uses process hollowing and Regsvr32 to execute another payload. |
| T1057 Process Discovery |
Orz can gather a process list from the victim. |
| T1059.003 Windows Command Shell |
Orz can execute shell commands. Orz can execute commands with JavaScript. |
| T1070 Indicator Removal |
Orz can overwrite Registry settings to reduce its visibility on the victim. |
| T1082 System Information Discovery |
Orz can gather the victim OS version and whether it is 64 or 32 bit. |
| T1083 File and Directory Discovery |
Orz can gather victim drive information. |
| T1102.002 Bidirectional Communication |
Orz has used Technet and Pastebin web pages for command and control. |
| T1105 Ingress Tool Transfer |
Orz can download files onto the victim. |
| T1112 Modify Registry |
Orz can perform Registry operations. |
| T1218.010 Regsvr32 |
Some Orz versions have an embedded DLL known as MockDll that uses Process Hollowing and regsvr32 to execute another payload. |
| T1518 Software Discovery |
Orz can gather the victim's Internet Explorer version. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.