ATT&CKReferencesCheckPoint Volatile Cedar March 2015

CheckPoint Volatile Cedar March 2015

Threat Intelligence and Research. (2015, March 30). VOLATILE CEDAR. Retrieved February 8, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareExplosive

Explosive has collected the MAC address from the victim's machine.

T1025
Data from Removable Media
MalwareExplosive

Explosive can scan all .exe files located in the USB drive.

T1033
System Owner/User Discovery
MalwareExplosive

Explosive has collected the username from the infected host.

T1056.001
Keylogging
MalwareExplosive

Explosive has leveraged its keylogging capabilities to gain access to administrator accounts on target servers.

T1071.001
Web Protocols
MalwareExplosive

Explosive has used HTTP for communication.

T1082
System Information Discovery
MalwareExplosive

Explosive has collected the computer name from the infected host.

T1105
Ingress Tool Transfer
MalwareExplosive

Explosive has a function to download a file to the infected system.

T1106
Native API
MalwareExplosive

Explosive has a function to call the OpenClipboard wrapper.

T1112
Modify Registry
MalwareExplosive

Explosive has a function to write itself to Registry values.

T1115
Clipboard Data
MalwareExplosive

Explosive has a function to use the OpenClipboard wrapper.

T1190
Exploit Public-Facing Application
GroupVolatile Cedar

Volatile Cedar has targeted publicly facing web servers, with both automatic and manual vulnerability discovery.

T1505.003
Web Shell
GroupVolatile Cedar

Volatile Cedar can inject web shell code into a server.

T1564.001
Hidden Files and Directories
MalwareExplosive

Explosive has commonly set file and path attributes to hidden.

T1595.002
Vulnerability Scanning
GroupVolatile Cedar

Volatile Cedar has performed vulnerability scans of the target server.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.