Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
XLoader uses various packers, including CyaX, to obfuscate malicious executables. |
| T1027.013 Encrypted/Encoded File |
XLoader features encrypted functions using the RC4 algorithm and bytecode operations. |
| T1033 System Owner/User Discovery |
XLoader can identify the username from a victim machine. |
| T1053.005 Scheduled Task |
XLoader can create scheduled tasks for persistence. |
| T1055.004 Asynchronous Procedure Call |
XLoader injects code into the APC queue using `NtQueueApcThread` API. |
| T1055.012 Process Hollowing |
XLoader uses process hollowing by injecting itself into the `explorer.exe` process and other files ithin the Windows `SysWOW64` directory. |
| T1056.001 Keylogging |
XLoader can capture keystrokes from the victim machine. |
| T1059.010 AutoHotKey & AutoIT |
XLoader can use an AutoIT script to decrypt a payload file, load it into victim memory, then execute it on the victim machine. |
| T1070.004 File Deletion |
XLoader can delete malicious executables from compromised machines. |
| T1071.001 Web Protocols |
XLoader uses HTTP and HTTPS for command and control communication. |
| T1082 System Information Discovery |
XLoader can collect system information and supported language information from the victim machine. |
| T1106 Native API |
XLoader uses the native Windows API for functionality, including defense evasion. |
| T1113 Screen Capture |
XLoader can capture screenshots on compromised hosts. |
| T1115 Clipboard Data |
XLoader can collect data stored in the victim's clipboard. |
| T1140 Deobfuscate/Decode Files or Information |
XLoader uses XOR and RC4 algorithms to decrypt payloads and functions. XLoader can be distributed as a self-extracting RAR archive that launches an AutoIT loader. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.