Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
Denis queries the Registry for keys and values. |
| T1016 System Network Configuration Discovery |
Denis uses |
| T1027 Obfuscated Files or Information |
Denis obfuscates its code and encrypts the API names. |
| T1027.010 Command Obfuscation |
Denis has encoded its PowerShell commands in Base64. |
| T1033 System Owner/User Discovery |
Denis enumerates and collects the username from the victim’s machine. |
| T1055.012 Process Hollowing |
Denis performed process hollowing through the API calls CreateRemoteThread, ResumeThread, and Wow64SetThreadContext. |
| T1059.001 PowerShell |
Denis has a version written in PowerShell. |
| T1059.003 Windows Command Shell |
Denis can launch a remote shell to execute arbitrary commands on the victim’s machine. |
| T1070.004 File Deletion |
Denis has a command to delete files from the victim’s machine. |
| T1071.004 DNS |
Denis has used DNS tunneling for C2 communications. |
| T1082 System Information Discovery |
Denis collects OS information and the computer name from the victim’s machine. |
| T1083 File and Directory Discovery |
Denis has several commands to search directories for files. |
| T1105 Ingress Tool Transfer |
Denis deploys additional backdoors and hacking tools to the system. |
| T1106 Native API |
Denis used the |
| T1132.001 Standard Encoding |
Denis encodes the data sent to the server in Base64. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.