Miller-Osborn, J. and Grunzweig, J.. (2017, February 16). menuPass Returns with New Malware and New Attacks Against Japanese Academics and Organizations. Retrieved March 1, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareChChes | ChChes collects its process identifier (PID) on the victim. |
| T1071.001 Web Protocols |
MalwareChChes | ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header. |
| T1082 System Information Discovery |
MalwareChChes | ChChes collects the victim hostname, window resolution, and Microsoft Windows version. |
| T1105 Ingress Tool Transfer |
MalwareChChes | ChChes is capable of downloading files, including additional modules. |
| T1132.001 Standard Encoding |
MalwareChChes | ChChes can encode C2 data with a custom technique that utilizes Base64. |
| T1553.002 Code Signing |
MalwareChChes | ChChes samples were digitally signed with a certificate originally used by Hacking Team that was later leaked and subsequently revoked. |
| T1573.001 Symmetric Cryptography |
MalwareChChes | ChChes can encrypt C2 traffic with AES or RC4. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.