Chen, J. and Hsieh, M. (2017, November 7). REDBALDKNIGHT/BRONZE BUTLER’s Daserf Backdoor Now Using Steganography. Retrieved December 27, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.002 Steganography |
MalwareDaserf | Daserf can use steganography to hide malicious code downloaded to the victim. |
| T1027 Obfuscated Files or Information |
MalwareDaserf | Daserf uses encrypted Windows APIs and also encrypts data using the alternative base64+RC4 or the Caesar cipher. |
| T1027.002 Software Packing |
MalwareDaserf | A version of Daserf uses the MPRESS packer. |
| T1027.005 Indicator Removal from Tools |
MalwareDaserf | Analysis of Daserf has shown that it regularly undergoes technical improvements to evade anti-virus detection. |
| T1056.001 Keylogging |
MalwareDaserf | Daserf can log keystrokes. |
| T1059.003 Windows Command Shell |
MalwareDaserf | Daserf can execute shell commands. |
| T1105 Ingress Tool Transfer |
MalwareDaserf | Daserf can download remote files. |
| T1113 Screen Capture |
MalwareDaserf | Daserf can take screenshots. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.