Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
ShadowPad has collected the domain name of the victim system. |
| T1027 Obfuscated Files or Information |
ShadowPad has encrypted its payload, a virtual file system, and various files. |
| T1027.011 Fileless Storage |
ShadowPad maintains a configuration block and virtual file system in the Registry. |
| T1029 Scheduled Transfer |
ShadowPad has sent data back to C2 every 8 hours. |
| T1033 System Owner/User Discovery |
ShadowPad has collected the username of the victim system. |
| T1055 Process Injection |
ShadowPad has injected an install module into a newly created process. |
| T1055.001 Dynamic-link Library Injection |
ShadowPad has injected a DLL into svchost.exe. |
| T1057 Process Discovery |
ShadowPad has collected the PID of a malicious process. |
| T1070 Indicator Removal |
ShadowPad has deleted arbitrary Registry values. |
| T1071.001 Web Protocols |
ShadowPad communicates over HTTP to retrieve a string that is decoded into a C2 server URL. |
| T1071.002 File Transfer Protocols |
ShadowPad has used FTP for C2 communications. |
| T1071.004 DNS |
ShadowPad has used DNS tunneling for C2 communications. |
| T1082 System Information Discovery |
ShadowPad has discovered system information including memory status, CPU frequency, and OS versions. |
| T1095 Non-Application Layer Protocol |
ShadowPad has used UDP for C2 communications. |
| T1105 Ingress Tool Transfer |
ShadowPad has downloaded code from a C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.