Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1008 Fallback Channels |
Anchor can use secondary C2 servers for communication after establishing connectivity and relaying victim information to primary C2 servers. |
| T1016 System Network Configuration Discovery |
Anchor can determine the public IP and location of a compromised host. |
| T1021.002 SMB/Windows Admin Shares |
Anchor can support windows execution via SMB shares. |
| T1027 Obfuscated Files or Information |
Anchor has obfuscated code with stack strings and string encryption. |
| T1027.002 Software Packing |
Anchor has come with a packed payload. |
| T1053.003 Cron |
Anchor can install itself as a cron job. |
| T1053.005 Scheduled Task |
Anchor can create a scheduled task for persistence. |
| T1059.003 Windows Command Shell |
Anchor has used cmd.exe to run its self deletion routine. |
| T1059.004 Unix Shell |
Anchor can execute payloads via shell scripting. |
| T1070.004 File Deletion |
Anchor can self delete its dropper after the malware is successfully deployed. |
| T1071.001 Web Protocols |
Anchor has used HTTP and HTTPS in C2 communications. |
| T1071.004 DNS |
Variants of Anchor can use DNS tunneling to communicate with C2. |
| T1082 System Information Discovery |
Anchor can determine the hostname and linux version on a compromised host. |
| T1095 Non-Application Layer Protocol |
Anchor has used ICMP in C2 communications. |
| T1105 Ingress Tool Transfer |
Anchor can download additional payloads. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.