Malware.View on attack.mitre.org
PowerShower is a PowerShell backdoor used by Inception for initial reconnaissance and to download and execute second stage payloads.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
PowerShower has the ability to identify the current Windows domain of the infected host. |
| T1033 System Owner/User Discovery |
PowerShower has the ability to identify the current user on the infected host. |
| T1041 Exfiltration Over C2 Channel |
PowerShower has used a PowerShell document stealer module to pack and exfiltrate .txt, .pdf, .xls or .doc files smaller than 5MB that were modified during the past two days. |
| T1057 Process Discovery |
PowerShower has the ability to deploy a reconnaissance module to retrieve a list of the active processes. |
| T1059.001 PowerShell |
PowerShower is a backdoor written in PowerShell. |
| T1059.005 Visual Basic |
PowerShower has the ability to save and execute VBScript. |
| T1070.004 File Deletion |
PowerShower has the ability to remove all files created during the dropper process. |
| T1071.001 Web Protocols |
PowerShower has sent HTTP GET and POST requests to C2 servers to send information and receive instructions. |
| T1082 System Information Discovery |
PowerShower has collected system information on the infected host. |
| T1112 Modify Registry |
PowerShower has added a registry key so future powershell.exe instances are spawned off-screen by default, and has removed all registry entries that are left behind during the dropper process. |
| T1132.001 Standard Encoding |
PowerShower has the ability to encode C2 communications with base64 encoding. |
| T1547.001 Registry Run Keys / Startup Folder |
PowerShower sets up persistence with a Registry run key. |
| T1560.001 Archive via Utility |
PowerShower has used 7Zip to compress .txt, .pdf, .xls or .doc files prior to exfiltration. |
| T1564.003 Hidden Window |
PowerShower has added a registry key so future powershell.exe instances are spawned with coordinates for a window position off-screen by default. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.