Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Shark can upload files to its C2. |
| T1008 Fallback Channels |
Shark can update its configuration to use a different C2 server. |
| T1012 Query Registry |
Shark can query `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid` to retrieve the machine GUID. |
| T1027.013 Encrypted/Encoded File |
Shark can use encrypted and encoded files for C2 configuration. |
| T1029 Scheduled Transfer |
Shark can pause C2 communications for a specified time. |
| T1036.005 Match Legitimate Resource Name or Location |
Shark binaries have been named `audioddg.pdb` and `Winlangdb.pdb` in order to appear legitimate. |
| T1041 Exfiltration Over C2 Channel |
Shark has the ability to upload files from the compromised host over a DNS or HTTP C2 channel. |
| T1059.003 Windows Command Shell |
Shark has the ability to use `CMD` to execute commands. |
| T1070.004 File Deletion |
Shark can delete files downloaded to the compromised host. |
| T1071.001 Web Protocols |
Shark has the ability to use HTTP in C2 communications. |
| T1071.004 DNS |
Shark can use DNS in C2 communications. |
| T1074 Data Staged |
Shark has stored information in folders named `U1` and `U2` prior to exfiltration. |
| T1082 System Information Discovery |
Shark can collect the GUID of a targeted machine. |
| T1105 Ingress Tool Transfer |
Shark can download additional files from its C2 via HTTP or DNS. |
| T1140 Deobfuscate/Decode Files or Information |
Shark can extract and decrypt downloaded .zip files. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.