Proofpoint Staff. (2018, March 7). Leaked Ammyy Admin Source Code Turned into Malware. Retrieved May 28, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareFlawedAmmyy | FlawedAmmyy may obfuscate portions of the initial C2 handshake. |
| T1033 System Owner/User Discovery |
MalwareFlawedAmmyy | FlawedAmmyy enumerates the current user during the initial infection. |
| T1047 Windows Management Instrumentation |
MalwareFlawedAmmyy | FlawedAmmyy leverages WMI to enumerate anti-virus on the victim. |
| T1069.001 Local Groups |
MalwareFlawedAmmyy | FlawedAmmyy enumerates the privilege level of the victim during the initial infection. |
| T1071.001 Web Protocols |
MalwareFlawedAmmyy | FlawedAmmyy has used HTTP for C2. |
| T1082 System Information Discovery |
MalwareFlawedAmmyy | FlawedAmmyy can collect the victim's operating system and computer name during the initial infection. |
| T1120 Peripheral Device Discovery |
MalwareFlawedAmmyy | FlawedAmmyy will attempt to detect if a usable smart card is current inserted into a card reader. |
| T1204.001 Malicious Link |
GroupTA505 | TA505 has used lures to get users to click links in emails and attachments. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1204.002 Malicious File |
GroupTA505 | TA505 has used lures to get users to enable content in malicious attachments and execute malicious files contained in archives. For example, TA505 makes their malware look like legitimate Microsoft Word documents, .pdf and/or .lnk files. |
| T1518.001 Security Software Discovery |
MalwareFlawedAmmyy | FlawedAmmyy will attempt to detect anti-virus products during the initial infection. |
| T1566.001 Spearphishing Attachment |
GroupTA505 | TA505 has used spearphishing emails with malicious attachments to initially compromise victims. |
| T1573.001 Symmetric Cryptography |
MalwareFlawedAmmyy | FlawedAmmyy has used SEAL encryption during the initial C2 handshake. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.