Malware.View on attack.mitre.org
Spark is a Windows backdoor and has been in use since as early as 2017.
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
Spark has been packed with Enigma Protector to obfuscate its contents. |
| T1033 System Owner/User Discovery |
Spark has run the whoami command and has a built-in command to identify the user logged in. |
| T1041 Exfiltration Over C2 Channel |
Spark has exfiltrated data over the C2 channel. |
| T1059.003 Windows Command Shell |
Spark can use cmd.exe to run commands. |
| T1071.001 Web Protocols |
Spark has used HTTP POST requests to communicate with its C2 server to receive commands. |
| T1082 System Information Discovery |
Spark can collect the hostname, keyboard layout, and language from the system. |
| T1132.001 Standard Encoding |
Spark has encoded communications with the C2 server with base64. |
| T1140 Deobfuscate/Decode Files or Information |
Spark has used a custom XOR algorithm to decrypt the payload. |
| T1497.002 User Activity Based Checks |
Spark has used a splash screen to check whether an user actively clicks on the screen before running malicious code. |
| T1614.001 System Language Discovery |
Spark has checked the results of the |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.