Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1001.001 Junk Data |
UPSTYLE retrieves a non-existent webpage from the command and control server then parses commands from the resulting error logs to decode commands to the web shell. |
| T1027.013 Encrypted/Encoded File |
UPSTYLE stores primary content as base64-encoded objects. |
| T1036 Masquerading |
UPSTYLE has masqueraded filenames using examples such as `update.py`. |
| T1057 Process Discovery |
UPSTYLE has the ability to read `/proc/self/cmdline` to see if it is running as a monitored process. |
| T1059.006 Python |
UPSTYLE is a Python-based application. |
| T1070.004 File Deletion |
UPSTYLE removes `bootstrap.min.css` after parsing command and control instructions, restoring the file to its original state. |
| T1070.006 Timestomp |
UPSTYLE restores timestamps to original values following modification. |
| T1102.003 One-Way Communication |
UPSTYLE parses encoded commands from error logs after attempting to resolve a non-existing webpage from the command and control server. |
| T1140 Deobfuscate/Decode Files or Information |
UPSTYLE encodes its main content prior to loading via Python as base64-encoded blobs. |
| T1546 Event Triggered Execution |
UPSTYLE creates a `.pth` file beginning with the text `import` so that any time another process or script attempts to reference the modified item the malicious code will also run. |
| T1665 Hide Infrastructure |
UPSTYLE attempts to retrieve a non-existent webpage from the command and control server resulting in hidden commands sent via resulting error messages. |
| T1685.006 Clear Linux or Mac System Logs |
UPSTYLE clears error logs after reading embedded commands for execution. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.