Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1014 Rootkit |
Hildegard has modified /etc/ld.so.preload to overwrite readdir() and readdir64(). |
| T1027.002 Software Packing |
Hildegard has packed ELF files into other binaries. |
| T1027.013 Encrypted/Encoded File |
Hildegard has encrypted an ELF file. |
| T1036.004 Masquerade Task or Service |
Hildegard has disguised itself as a known Linux process. |
| T1046 Network Service Discovery |
Hildegard has used masscan to look for kubelets in the internal Kubernetes network. |
| T1059.004 Unix Shell |
Hildegard has used shell scripts for execution. |
| T1068 Exploitation for Privilege Escalation |
Hildegard has used the BOtB tool which exploits CVE-2019-5736. |
| T1070.003 Clear Command History |
Hildegard has used history -c to clear script shell logs. |
| T1070.004 File Deletion |
Hildegard has deleted scripts after execution. |
| T1071 Application Layer Protocol |
Hildegard has used an IRC channel for C2 communications. |
| T1082 System Information Discovery |
Hildegard has collected the host's OS, CPU, and memory information. |
| T1102 Web Service |
Hildegard has downloaded scripts from GitHub. |
| T1105 Ingress Tool Transfer |
Hildegard has downloaded additional scripts that build and run Monero cryptocurrency miners. |
| T1133 External Remote Services |
Hildegard was executed through an unsecure kubelet that allowed anonymous access to the victim environment. |
| T1136.001 Local Account |
Hildegard has created a user named “monerodaemon”. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.