Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Milan can upload files from a compromised host. |
| T1012 Query Registry |
Milan can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID. |
| T1016 System Network Configuration Discovery |
Milan can run `C:\Windows\system32\cmd.exe /c cmd /c ipconfig /all 2>&1` to discover network settings. |
| T1027.013 Encrypted/Encoded File |
Milan can encode files containing information about the targeted system. |
| T1033 System Owner/User Discovery |
Milan can identify users registered to a targeted machine. |
| T1036 Masquerading |
Milan has used an executable named `companycatalogue` to appear benign. |
| T1036.007 Double File Extension |
Milan has used an executable named `companycatalog.exe.config` to appear benign. |
| T1053.005 Scheduled Task |
Milan can establish persistence on a targeted host with scheduled tasks. |
| T1059.003 Windows Command Shell |
Milan can use `cmd.exe` for discovery actions on a targeted system. |
| T1070.004 File Deletion |
Milan can delete files via `C:\Windows\system32\cmd.exe /c ping 1.1.1.1 -n 1 -w 3000 > Nul & rmdir /s /q`. |
| T1071.001 Web Protocols |
Milan can use HTTPS for communication with C2. |
| T1071.004 DNS |
Milan has the ability to use DNS for C2 communications. |
| T1074.001 Local Data Staging |
Milan has saved files prior to upload from a compromised host to folders beginning with the characters `a9850d2f`. |
| T1082 System Information Discovery |
Milan can enumerate the targeted machine's name and GUID. |
| T1087.001 Local Account |
Milan has run `C:\Windows\system32\cmd.exe /c cmd /c dir c:\users\ /s 2>&1` to discover local accounts. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.