Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016.001 Internet Connection Discovery |
SUGARUSH has checked for internet connectivity from an infected host before attempting to establish a new TCP connection. |
| T1059.003 Windows Command Shell |
SUGARUSH has used `cmd` for execution on an infected host. |
| T1095 Non-Application Layer Protocol |
SUGARUSH has used TCP for C2. |
| T1543.003 Windows Service |
SUGARUSH has created a service named `Service1` for persistence. |
| T1571 Non-Standard Port |
SUGARUSH has used port 4585 for a TCP connection to its C2. |
| T1680 Local Storage Discovery |
MoonWind can obtain the number of drives on the victim machine. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.