Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Samurai can leverage an exfiltration module to download arbitrary files from compromised machines. |
| T1012 Query Registry |
Samurai can query `SOFTWARE\Microsoft\.NETFramework\policy\v2.0` for discovery. |
| T1027 Obfuscated Files or Information |
Samurai can encrypt the names of requested APIs. |
| T1027.004 Compile After Delivery |
Samurai can compile and execute downloaded modules at runtime. |
| T1027.007 Dynamic API Resolution |
Samurai can encrypt API name strings with an XOR-based algorithm. |
| T1027.015 Compression |
Samurai can deliver its final payload as a compressed, encrypted and base64-encoded blob. |
| T1036.005 Match Legitimate Resource Name or Location |
Samurai has created the directory `%COMMONPROGRAMFILES%\Microsoft Shared\wmi\` to contain DLLs for loading successive stages. |
| T1059.003 Windows Command Shell |
Samurai can use a remote command module for execution via the Windows command line. |
| T1071.001 Web Protocols |
Samurai can use a .NET HTTPListener class to receive and handle HTTP POST requests. |
| T1083 File and Directory Discovery |
Samurai can use a specific module for file enumeration. |
| T1090 Proxy |
Samurai has the ability to proxy connections to specified remote IPs and ports through a a proxy module. |
| T1095 Non-Application Layer Protocol |
Samurai can use a proxy module to forward TCP packets to external hosts. |
| T1105 Ingress Tool Transfer |
Samurai has been used to deploy other malware including Ninja. |
| T1106 Native API |
Samurai has the ability to call Windows APIs. |
| T1112 Modify Registry |
The Samurai loader component can create multiple Registry keys to force the svchost.exe process to load the final backdoor. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.