Malware.View on attack.mitre.org
Snip3 is a sophisticated crypter-as-a-service that has been used since at least 2021 to obfuscate and load numerous strains of malware including AsyncRAT, Revenge RAT, Agent Tesla, and NETWIRE.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Snip3 has the ability to obfuscate strings using XOR encryption. |
| T1027.001 Binary Padding |
Snip3 can obfuscate strings using junk Chinese characters. |
| T1047 Windows Management Instrumentation |
Snip3 can query the WMI class `Win32_ComputerSystem` to gather information. |
| T1055.012 Process Hollowing |
Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process. |
| T1059.001 PowerShell |
Snip3 can use a PowerShell script for second-stage execution. |
| T1059.005 Visual Basic |
Snip3 can use visual basic scripts for first-stage execution. |
| T1082 System Information Discovery |
Snip3 has the ability to query `Win32_ComputerSystem` for system information. |
| T1102 Web Service |
Snip3 can download additional payloads from web services including Pastebin and top4top. |
| T1104 Multi-Stage Channels |
Snip3 can download and execute additional payloads and modules over separate communication channels. |
| T1105 Ingress Tool Transfer |
Snip3 can download additional payloads to compromised systems. |
| T1140 Deobfuscate/Decode Files or Information |
Snip3 can decode its second-stage PowerShell script prior to execution. |
| T1189 Drive-by Compromise |
Snip3 has been delivered to targets via downloads from malicious domains. |
| T1204.001 Malicious Link |
Snip3 has been executed through luring victims into clicking malicious links. |
| T1204.002 Malicious File |
Snip3 can gain execution through the download of visual basic files. |
| T1497.001 System Checks |
Snip3 has the ability to detect Windows Sandbox, VMWare, or VirtualBox by querying `Win32_ComputerSystem` to extract the `Manufacturer` string. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.