ATT&CKReferencesPalo Alto menuPass Feb 2017

Palo Alto menuPass Feb 2017

Miller-Osborn, J. and Grunzweig, J.. (2017, February 16). menuPass Returns with New Malware and New Attacks Against Japanese Academics and Organizations. Retrieved March 1, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareChChes

ChChes collects its process identifier (PID) on the victim.

T1071.001
Web Protocols
MalwareChChes

ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header.

T1082
System Information Discovery
MalwareChChes

ChChes collects the victim hostname, window resolution, and Microsoft Windows version.

T1105
Ingress Tool Transfer
MalwareChChes

ChChes is capable of downloading files, including additional modules.

T1132.001
Standard Encoding
MalwareChChes

ChChes can encode C2 data with a custom technique that utilizes Base64.

T1553.002
Code Signing
MalwareChChes

ChChes samples were digitally signed with a certificate originally used by Hacking Team that was later leaked and subsequently revoked.

T1573.001
Symmetric Cryptography
MalwareChChes

ChChes can encrypt C2 traffic with AES or RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.