Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Nightdoor gathers information on victim system network configuration such as MAC addresses. |
| T1033 System Owner/User Discovery |
Nightdoor gathers information on victim system users and usernames. |
| T1053.005 Scheduled Task |
Nightdoor uses scheduled tasks for persistence to load the final malware payload into memory. |
| T1057 Process Discovery |
Nightdoor can collect information on installed applications via Windows registry keys, as well as collecting information on running processes. |
| T1059.003 Windows Command Shell |
Nightdoor creates a cmd.exe shell to send and receive commands from the command and control server via open pipes. |
| T1070.004 File Deletion |
Nightdoor can self-delete. |
| T1071 Application Layer Protocol |
Nightdoor uses TCP and UDP communication for command and control traffic. |
| T1082 System Information Discovery |
Nightdoor gathers information on the victim system such as CPU and Computer name as well as device drivers. |
| T1102 Web Service |
Nightdoor can utilize Microsoft OneDrive or Google Drive for command and control purposes. |
| T1124 System Time Discovery |
Nightdoor can identify the system local time information. |
| T1140 Deobfuscate/Decode Files or Information |
Nightdoor stores network configuration data in a file XOR encoded with the key value of `0x7A`. |
| T1497.001 System Checks |
Nightdoor embeds code from the public `al-khaser` project, a repository that works to detect virtual machines, sandboxes, and malware analysis environments. |
| T1574 Hijack Execution Flow |
Nightdoor uses a legitimate executable to load a malicious DLL file for installation. |
| T1680 Local Storage Discovery |
Nightdoor can collect information about disk drives, their total and free space, and file system type. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.