Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Flagpro can collect data from a compromised host, including Windows authentication information. |
| T1010 Application Window Discovery |
Flagpro can check the name of the window displayed on the system. |
| T1016 System Network Configuration Discovery |
Flagpro has been used to execute the |
| T1018 Remote System Discovery |
Flagpro has been used to execute |
| T1027 Obfuscated Files or Information |
Flagpro has been delivered within ZIP or RAR password-protected archived files. |
| T1029 Scheduled Transfer |
Flagpro has the ability to wait for a specified time interval between communicating with and executing commands from C2. |
| T1033 System Owner/User Discovery |
Flagpro has been used to run the |
| T1036 Masquerading |
Flagpro can download malicious files with a .tmp extension and append them with .exe prior to execution. |
| T1041 Exfiltration Over C2 Channel |
Flagpro has exfiltrated data to the C2 server. |
| T1049 System Network Connections Discovery |
Flagpro has been used to execute |
| T1057 Process Discovery |
Flagpro has been used to run the |
| T1059.003 Windows Command Shell |
Flagpro can use `cmd.exe` to execute commands received from C2. |
| T1059.005 Visual Basic |
Flagpro can execute malicious VBA macros embedded in .xlsm files. |
| T1069.001 Local Groups |
Flagpro has been used to execute the |
| T1070 Indicator Removal |
Flagpro can close specific Windows Security and Internet Explorer dialog boxes to mask external connections. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.