Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Gelsemium can collect data from a compromised host. |
| T1008 Fallback Channels |
Gelsemium can use multiple domains and protocols in C2. |
| T1012 Query Registry |
Gelsemium can open random files and Registry keys to obscure malware behavior from sandbox analysis. |
| T1027.011 Fileless Storage |
Gelsemium can store its components in the Registry. |
| T1027.015 Compression |
Gelsemium has the ability to compress its components. |
| T1027.016 Junk Code Insertion |
Gelsemium can use junk code to hide functions and evade detection. |
| T1033 System Owner/User Discovery |
Gelsemium has the ability to distinguish between a standard user and an administrator on a compromised host. |
| T1036.001 Invalid Code Signature |
Gelsemium has used unverified signatures on malicious DLLs. |
| T1036.005 Match Legitimate Resource Name or Location |
Gelsemium has named malicious binaries `serv.exe`, `winprint.dll`, and `chrome_elf.dll` and has set its persistence in the Registry with the key value |
| T1055.001 Dynamic-link Library Injection |
Gelsemium has the ability to inject DLLs into specific processes. |
| T1057 Process Discovery |
Gelsemium can enumerate running processes. |
| T1059.003 Windows Command Shell |
Gelsemium can use a batch script to delete itself. |
| T1070.004 File Deletion |
Gelsemium can delete its dropper component from the targeted system. |
| T1070.006 Timestomp |
Gelsemium has the ability to perform timestomping of files on targeted systems. |
| T1071.001 Web Protocols |
Gelsemium can use HTTP/S in C2 communications. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.