Malware.View on attack.mitre.org
Remexi is a Windows-based Trojan that was developed in the C programming language.
| Technique | Procedure example |
|---|---|
| T1010 Application Window Discovery |
Remexi has a command to capture active windows on the machine and retrieve window titles. |
| T1027.013 Encrypted/Encoded File |
Remexi obfuscates its configuration data with XOR. |
| T1041 Exfiltration Over C2 Channel |
Remexi performs exfiltration over BITSAdmin, which is also used for the C2 channel. |
| T1047 Windows Management Instrumentation |
Remexi executes received commands with wmic.exe (for WMI commands). |
| T1053.005 Scheduled Task |
Remexi utilizes scheduled tasks as a persistence mechanism. |
| T1056.001 Keylogging |
Remexi gathers and exfiltrates keystrokes from the machine. |
| T1059.003 Windows Command Shell |
Remexi silently executes received commands with cmd.exe. |
| T1059.005 Visual Basic |
Remexi uses AutoIt and VBS scripts throughout its execution process. |
| T1071.001 Web Protocols |
Remexi uses BITSAdmin to communicate with the C2 server over HTTP. |
| T1083 File and Directory Discovery |
Remexi searches for files on the system. |
| T1113 Screen Capture |
Remexi takes screenshots of windows of interest. |
| T1115 Clipboard Data |
Remexi collects text from the clipboard. |
| T1140 Deobfuscate/Decode Files or Information |
Remexi decrypts the configuration data using XOR with 25-character keys. |
| T1547.001 Registry Run Keys / Startup Folder |
Remexi utilizes Run Registry keys in the HKLM hive as a persistence mechanism. |
| T1547.004 Winlogon Helper DLL |
Remexi achieves persistence using Userinit by adding the Registry key |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.