Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1069.001 Local Groups |
Exbyte checks whether the process is running with privileged local access during execution. |
| T1070.004 File Deletion |
Exbyte will self-delete if a hard-coded configuration file is not found. |
| T1083 File and Directory Discovery |
Exbyte enumerates all document files on an infected machine, then creates a summary of these items including filename and directory location prior to exfiltration to cloud hosting services. |
| T1106 Native API |
Exbyte calls `ShellExecuteW` with the `IpOperation` parameter `RunAs` to launch `explorer.exe` with elevated privileges. |
| T1140 Deobfuscate/Decode Files or Information |
Exbyte decodes and decrypts data stored in the configuration file with a key provided on the command line during execution. |
| T1480 Execution Guardrails |
Exbyte checks for the presence of a configuration file before completing execution. |
| T1497.001 System Checks |
Exbyte performs various checks to determine if it is running in a sandboxed environment to prevent analysis. |
| T1518.001 Security Software Discovery |
Exbyte checks for the presence of various security software products during execution. |
| T1567 Exfiltration Over Web Service |
Exbyte exfiltrates collected data to online file hosting sites such as `Mega.co.nz`. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.