Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1010 Application Window Discovery |
Attor can obtain application window titles and then determines which windows to perform Screen Capture on. |
| T1012 Query Registry |
Attor has opened the registry and performed query searches. |
| T1020 Automated Exfiltration |
Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server. |
| T1027.013 Encrypted/Encoded File |
Strings in Attor's components are encrypted with a XOR cipher, using a hardcoded key and the configuration data, log files and plugins are encrypted using a hybrid encryption scheme of Blowfish-OFB combined with RSA. |
| T1036.004 Masquerade Task or Service |
Attor's dispatcher disguises itself as a legitimate task (i.e., the task name and description appear legitimate). |
| T1037.001 Logon Script (Windows) |
Attor's dispatcher can establish persistence via adding a Registry key with a logon script |
| T1041 Exfiltration Over C2 Channel |
Attor has exfiltrated data over the C2 channel. |
| T1053.005 Scheduled Task |
Attor's installer plugin can schedule a new task that loads the dispatcher on boot/logon. |
| T1055 Process Injection |
Attor's dispatcher can inject itself into running processes to gain higher privileges and to evade detection. |
| T1055.004 Asynchronous Procedure Call |
Attor performs the injection by attaching its code into the APC queue using NtQueueApcThread API. |
| T1056.001 Keylogging |
One of Attor's plugins can collect user credentials via capturing keystrokes and can capture keystrokes pressed within the window of the injected process. |
| T1070.004 File Deletion |
Attor’s plugin deletes the collected files and log files after exfiltration. |
| T1070.006 Timestomp |
Attor has manipulated the time of last access to files and registry keys after they have been created or modified. |
| T1071.002 File Transfer Protocols |
Attor has used FTP protocol for C2 communication. |
| T1074.001 Local Data Staging |
Attor has staged collected data in a central upload directory prior to exfiltration. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.