Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
Fysbis has been encrypted using XOR and RC4. |
| T1036.004 Masquerade Task or Service |
Fysbis has masqueraded as the rsyncd and dbus-inotifier services. |
| T1036.005 Match Legitimate Resource Name or Location |
Fysbis has masqueraded as trusted software rsyncd and dbus-inotifier. |
| T1056.001 Keylogging |
Fysbis can perform keylogging. |
| T1057 Process Discovery |
Fysbis can collect information about running processes. |
| T1059.004 Unix Shell |
Fysbis has the ability to create and execute commands in a remote shell for CLI. |
| T1070.004 File Deletion |
Fysbis has the ability to delete files. |
| T1082 System Information Discovery |
Fysbis has used the command |
| T1083 File and Directory Discovery |
Fysbis has the ability to search for files. |
| T1132.001 Standard Encoding |
Fysbis can use Base64 to encode its C2 traffic. |
| T1543.002 Systemd Service |
Fysbis has established persistence using a systemd service. |
| T1547.013 XDG Autostart Entries |
If executing without root privileges, Fysbis adds a `.desktop` configuration file to the user's `~/.config/autostart` directory. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.