Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1018 Remote System Discovery |
BADHATCH can use a PowerShell object such as, `System.Net.NetworkInformation.Ping` to ping a computer. |
| T1027.009 Embedded Payloads |
BADHATCH has an embedded second stage DLL payload within the first stage of the malware. |
| T1027.010 Command Obfuscation |
BADHATCH malicious PowerShell commands can be encoded with base64. |
| T1027.015 Compression |
BADHATCH can be compressed with the ApLib algorithm. |
| T1033 System Owner/User Discovery |
BADHATCH can obtain logged user information from a compromised machine and can execute the command `whoami.exe`. |
| T1041 Exfiltration Over C2 Channel |
BADHATCH can exfiltrate data over the C2 channel. |
| T1046 Network Service Discovery |
BADHATCH can check for open ports on a computer by establishing a TCP connection. |
| T1047 Windows Management Instrumentation |
BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine. |
| T1049 System Network Connections Discovery |
BADHATCH can execute `netstat.exe -f` on a compromised machine. |
| T1053.005 Scheduled Task |
BADHATCH can use `schtasks.exe` to gain persistence. |
| T1055 Process Injection |
BADHATCH can inject itself into an existing explorer.exe process by using `RtlCreateUserThread`. |
| T1055.001 Dynamic-link Library Injection |
BADHATCH has the ability to execute a malicious DLL by injecting into `explorer.exe` on a compromised machine. |
| T1055.004 Asynchronous Procedure Call |
BADHATCH can inject itself into a new `svchost.exe -k netsvcs` process using the asynchronous procedure call (APC) queue. |
| T1057 Process Discovery |
BADHATCH can retrieve a list of running processes from a compromised machine. |
| T1059.001 PowerShell |
BADHATCH can utilize `powershell.exe` to execute commands on a compromised host. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.