Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
Kerrdown can encrypt, encode, and compress multiple layers of shellcode. |
| T1027.015 Compression |
Kerrdown can encrypt, encode, and compress multiple layers of shellcode. |
| T1059.005 Visual Basic |
Kerrdown can use a VBS base64 decoder function published by Motobit. |
| T1082 System Information Discovery |
Kerrdown has the ability to determine if the compromised host is running a 32 or 64 bit OS architecture. |
| T1105 Ingress Tool Transfer |
Kerrdown can download specific payloads to a compromised host based on OS architecture. |
| T1140 Deobfuscate/Decode Files or Information |
Kerrdown can decode, decrypt, and decompress multiple layers of shellcode. |
| T1204.001 Malicious Link |
Kerrdown has gained execution through victims opening malicious links. |
| T1204.002 Malicious File |
Kerrdown has gained execution through victims opening malicious files. |
| T1566.001 Spearphishing Attachment |
Kerrdown has been distributed through malicious e-mail attachments. |
| T1566.002 Spearphishing Link |
Kerrdown has been distributed via e-mails containing a malicious link. |
| T1574.001 DLL |
Kerrdown can use DLL side-loading to load malicious DLLs. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.