Nicolas Falliere, Liam O Murchu, Eric Chien 2011, February W32.Stuxnet Dossier (Version 1.4) Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareStuxnet | Stuxnet has the ability to generate new C2 domains. |
| T1012 Query Registry |
MalwareStuxnet | Stuxnet searches the Registry for indicators of security programs. |
| T1014 Rootkit |
MalwareStuxnet | Stuxnet uses a Windows rootkit to mask its binaries and other relevant files. |
| T1016 System Network Configuration Discovery |
MalwareStuxnet | Stuxnet collects the IP address of a compromised system. |
| T1021 Remote Services |
MalwareStuxnet | Stuxnet can propagate via peer-to-peer communication and updates using RPC. |
| T1021.002 SMB/Windows Admin Shares |
MalwareStuxnet | Stuxnet propagates to available network shares. |
| T1027.013 Encrypted/Encoded File |
MalwareStuxnet | Stuxnet uses encrypted configuration blocks and writes encrypted files to disk. |
| T1041 Exfiltration Over C2 Channel |
MalwareStuxnet | Stuxnet sends compromised victim information via HTTP. |
| T1047 Windows Management Instrumentation |
MalwareStuxnet | Stuxnet used WMI with an |
| T1053.005 Scheduled Task |
MalwareStuxnet | Stuxnet schedules a network job to execute two minutes after host infection. |
| T1055.001 Dynamic-link Library Injection |
MalwareStuxnet | Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process. |
| T1068 Exploitation for Privilege Escalation |
MalwareStuxnet | Stuxnet used MS10-073 and an undisclosed Task Scheduler vulnerability to escalate privileges on local Windows machines. |
| T1070 Indicator Removal |
MalwareStuxnet | Stuxnet can delete OLE Automation and SQL stored procedures used to store malicious payloads. |
| T1070.004 File Deletion |
MalwareStuxnet | Stuxnet uses an RPC server that contains a routine for file deletion and also removes itself from the system through a DLL export by deleting specific files. |
| T1070.006 Timestomp |
MalwareStuxnet | Stuxnet extracts and writes driver files that match the times of other legitimate files. |
| T1071.001 Web Protocols |
MalwareStuxnet | Stuxnet uses HTTP to communicate with a command and control server. |
| T1078.001 Default Accounts |
MalwareStuxnet | Stuxnet infected WinCC machines via a hardcoded database server password. |
| T1078.002 Domain Accounts |
MalwareStuxnet | Stuxnet attempts to access network resources with a domain account’s credentials. |
| T1080 Taint Shared Content |
MalwareStuxnet | Stuxnet infects remote servers via network shares and by infecting WinCC database views with malicious code. |
| T1082 System Information Discovery |
MalwareStuxnet | Stuxnet collects system information including computer and domain names, OS version, and S7P paths. |
| T1083 File and Directory Discovery |
MalwareStuxnet | Stuxnet uses a driver to scan for specific filesystem driver objects. |
| T1087.001 Local Account |
MalwareStuxnet | Stuxnet enumerates user accounts of the local host. |
| T1087.002 Domain Account |
MalwareStuxnet | Stuxnet enumerates user accounts of the domain. |
| T1090.001 Internal Proxy |
MalwareStuxnet | Stuxnet installs an RPC server for P2P communications. |
| T1091 Replication Through Removable Media |
MalwareStuxnet | Stuxnet can propagate via removable media using an autorun.inf file or the CVE-2010-2568 LNK vulnerability. |
| T1106 Native API |
MalwareStuxnet | Stuxnet uses the SetSecurityDescriptorDacl API to reduce object integrity levels. |
| T1112 Modify Registry |
MalwareStuxnet | Stuxnet can create registry keys to load driver files. |
| T1120 Peripheral Device Discovery |
MalwareStuxnet | Stuxnet enumerates removable drives for infection. |
| T1124 System Time Discovery |
MalwareStuxnet | Stuxnet collects the time and date of a system when it is infected. |
| T1129 Shared Modules |
MalwareStuxnet | Stuxnet calls LoadLibrary then executes exports from a DLL. |
| T1132.001 Standard Encoding |
MalwareStuxnet | Stuxnet transforms encrypted binary data into an ASCII string in order to use it as a URL parameter value. |
| T1134.001 Token Impersonation/Theft |
MalwareStuxnet | Stuxnet attempts to impersonate an anonymous token to enumerate bindings in the service control manager. |
| T1135 Network Share Discovery |
MalwareStuxnet | Stuxnet enumerates the directories of a network resource. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStuxnet | Stuxnet decrypts resources that are loaded into memory and executed. |
| T1210 Exploitation of Remote Services |
MalwareStuxnet | Stuxnet propagates using the MS10-061 Print Spooler and MS08-067 Windows Server Service vulnerabilities. |
| T1480 Execution Guardrails |
MalwareStuxnet | Stuxnet checks for specific operating systems on 32-bit machines, Registry keys, and dates for vulnerabilities, and will exit execution if the values are not met. |
| T1505.001 SQL Stored Procedures |
MalwareStuxnet | Stuxnet used xp_cmdshell to store and execute SQL code. |
| T1518.001 Security Software Discovery |
MalwareStuxnet | Stuxnet enumerates the currently running processes related to a variety of security products. |
| T1543.003 Windows Service |
MalwareStuxnet | Stuxnet uses a driver registered as a boot start service as the main load-point. |
| T1553.002 Code Signing |
MalwareStuxnet | Stuxnet used a digitally signed driver with a compromised Realtek certificate. |
| T1560.003 Archive via Custom Method |
MalwareStuxnet | Stuxnet encrypts exfiltrated data via C2 with static 31-byte long XOR keys. |
| T1570 Lateral Tool Transfer |
MalwareStuxnet | Stuxnet uses an RPC server that contains a file dropping routine and support for payload version updates for P2P communications within a victim network. |
| T1573.001 Symmetric Cryptography |
MalwareStuxnet | Stuxnet encodes the payload of system information sent to the command and control servers using a one byte 0xFF XOR key. Stuxnet also uses a 31-byte long static byte string to XOR data sent to command and control servers. The servers use a different static key to encrypt replies to the implant. |
| T1685 Disable or Modify Tools |
MalwareStuxnet | Stuxnet reduces the integrity level of objects to allow write actions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.