Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1033 System Owner/User Discovery |
RGDoor executes the |
| T1059.003 Windows Command Shell |
RGDoor uses cmd.exe to execute commands on the victim’s machine. |
| T1071.001 Web Protocols |
RGDoor uses HTTP for C2 communications. |
| T1105 Ingress Tool Transfer |
RGDoor uploads and downloads files to and from the victim’s machine. |
| T1140 Deobfuscate/Decode Files or Information |
RGDoor decodes Base64 strings and decrypts strings using a custom XOR algorithm. |
| T1505.004 IIS Components |
RGDoor establishes persistence on webservers as an IIS module. |
| T1560.003 Archive via Custom Method |
RGDoor encrypts files with XOR before sending them back to the C2 server. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.