Malware.View on attack.mitre.org
SharpStage is a .NET malware with backdoor capabilities.
| Technique | Procedure example |
|---|---|
| T1047 Windows Management Instrumentation |
SharpStage can use WMI for execution. |
| T1053.005 Scheduled Task |
SharpStage has a persistence component to write a scheduled task for the payload. |
| T1059.001 PowerShell |
SharpStage can execute arbitrary commands with PowerShell. |
| T1059.003 Windows Command Shell |
SharpStage can execute arbitrary commands with the command line. |
| T1082 System Information Discovery |
SharpStage has checked the system settings to see if Arabic is the configured language. |
| T1102 Web Service |
SharpStage has used a legitimate web service for evading detection. |
| T1105 Ingress Tool Transfer |
SharpStage has the ability to download and execute additional payloads via a DropBox API. |
| T1113 Screen Capture |
SharpStage has the ability to capture the victim's screen. |
| T1140 Deobfuscate/Decode Files or Information |
SharpStage has decompressed data received from the C2 server. |
| T1547.001 Registry Run Keys / Startup Folder |
SharpStage has the ability to create persistence for the malware using the Registry autorun key and startup folder. |
| T1614.001 System Language Discovery |
SharpStage has been used to target Arabic-speaking users and used code that checks if the compromised machine has the Arabic language installed. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.