Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.010 Command Obfuscation |
IronWind has used Base64 encoding and XOR encryption with the key “53” to obfuscate command strings. |
| T1033 System Owner/User Discovery |
IronWind can enumerate the username on victim's systems. |
| T1059.003 Windows Command Shell |
IronWind has used the Windows command shell to execute malicious files. |
| T1070 Indicator Removal |
IronWind has used a .NET DLL named "exit-DN4-core.dll" to terminate malicious processes running on victim's systems. |
| T1071.001 Web Protocols |
IronWind can used HTTP to send information to C2 about the targeted system. |
| T1082 System Information Discovery |
IronWind can capture the OS version and computer name of the compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
IronWind can deobfuscate the next stage payload using Base64 and XOR operations with the key "53". |
| T1518 Software Discovery |
IronWind can list installed software on targeted hosts. |
| T1574.001 DLL |
IronWind has used DLL sideloading for execution. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.