Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1059.006 Python |
THINCRUST can use Python scripts for command execution. |
| T1071.001 Web Protocols |
THINCRUST can use HTTP POST requests in C2 communications. |
| T1140 Deobfuscate/Decode Files or Information |
THINCRUST can deobfuscate RSA encrypted C2 commands received through the DEVICEID cookie. |
| T1573.001 Symmetric Cryptography |
THINCRUST can process RSA encryted C2 commands. |
| T1686 Disable or Modify System Firewall |
THINCRUST can use the Django python module "django.views.decorators.csrf” along with the decorator “csrf_exempt” within victim firewalls to disable cross-site request forgery protections. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.