Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Machete searches the File system for files of interest. |
| T1008 Fallback Channels |
Machete has sent data over HTTP if FTP failed, and has also used a fallback server. |
| T1010 Application Window Discovery |
Machete saves the window names. |
| T1016 System Network Configuration Discovery |
Machete collects the MAC address of the target computer and other network configuration information. |
| T1016.002 Wi-Fi Discovery |
Machete uses the |
| T1020 Automated Exfiltration |
Machete’s collected files are exfiltrated automatically to remote servers. |
| T1025 Data from Removable Media |
Machete can find, encrypt, and upload files from fixed and removable drives. |
| T1027.002 Software Packing |
Machete has been packed with NSIS. |
| T1027.010 Command Obfuscation |
Machete has used pyobfuscate, zlib compression, and base64 encoding for obfuscation. Machete has also used some visual obfuscation techniques by naming variables as combinations of letters to hinder analysis. |
| T1029 Scheduled Transfer |
Machete sends stolen data to the C2 server every 10 minutes. |
| T1036.004 Masquerade Task or Service |
Machete renamed task names to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python tasks. |
| T1036.005 Match Legitimate Resource Name or Location |
Machete renamed payloads to masquerade as legitimate Google Chrome, Java, Dropbox, Adobe Reader and Python executables. |
| T1041 Exfiltration Over C2 Channel |
Machete's collected data is exfiltrated over the same channel used for C2. |
| T1052.001 Exfiltration over USB |
Machete has a feature to copy files from every drive onto a removable drive in a hidden folder. |
| T1053.005 Scheduled Task |
The different components of Machete are executed by Windows Task Scheduler. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.