Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
The AshTag AshenOrchestrator component payload as been Base64 encoded and embedded with HTML content from the C2 server. |
| T1036.005 Match Legitimate Resource Name or Location |
AshTag has masqueraded as a legitimate VisualServer utility. |
| T1041 Exfiltration Over C2 Channel |
AshTag has exfiltrated reconnaissance data on targeted systems to C2 servers. |
| T1047 Windows Management Instrumentation |
AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2. |
| T1053.005 Scheduled Task |
AshTag can set persistence using scheduled tasks. |
| T1057 Process Discovery |
The AshTag AshenOrchestrator component has process management functionality. |
| T1059.007 JavaScript |
AshTag can use JSON files to deliver payloads and configuration files. |
| T1071.001 Web Protocols |
AshTag can use HTTP to send and receive data from C2. |
| T1082 System Information Discovery |
The AshTag loader and AshenOrchestrator components can collect reconnaissance data from victim machines. |
| T1083 File and Directory Discovery |
The AshTag AshenOrchestrator component can enumerate files on victim hosts. |
| T1102 Web Service |
AshTag can download malicious payloads from file sharing services. |
| T1105 Ingress Tool Transfer |
The AshTag stager component can retrieve and execute the main payload. |
| T1113 Screen Capture |
The AshTag AshenOrchestrator component has the ability to take screenshots. |
| T1140 Deobfuscate/Decode Files or Information |
The AshTag stager compoment can decode and decrypt Base64 and XOR-encrypted payloads. |
| T1204.002 Malicious File |
AshTag has been executed through victims downloading and opening malicious RAR archive files. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.