Jornet, A. (2021, December 23). Snip3, an investigation into malware. Retrieved September 19, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
ToolAsyncRAT | AsyncRAT can check if the current user of a compromised system is an administrator. |
| T1053.005 Scheduled Task |
ToolAsyncRAT | AsyncRAT can create a scheduled task to maintain persistence on system start-up. |
| T1055.012 Process Hollowing |
MalwareSnip3 | Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process. |
| T1057 Process Discovery |
ToolAsyncRAT | AsyncRAT can examine running processes to determine if a debugger is present. |
| T1059.001 PowerShell |
MalwareSnip3 | Snip3 can use a PowerShell script for second-stage execution. |
| T1059.005 Visual Basic |
MalwareSnip3 | Snip3 can use visual basic scripts for first-stage execution. |
| T1104 Multi-Stage Channels |
MalwareSnip3 | Snip3 can download and execute additional payloads and modules over separate communication channels. |
| T1105 Ingress Tool Transfer |
MalwareSnip3 | Snip3 can download additional payloads to compromised systems. |
| T1106 Native API |
ToolAsyncRAT | AsyncRAT has the ability to use OS APIs including `CheckRemoteDebuggerPresent`. |
| T1189 Drive-by Compromise |
MalwareSnip3 | Snip3 has been delivered to targets via downloads from malicious domains. |
| T1204.001 Malicious Link |
MalwareSnip3 | Snip3 has been executed through luring victims into clicking malicious links. |
| T1204.002 Malicious File |
GroupTA2541 | TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads. |
| T1204.002 Malicious File |
MalwareSnip3 | Snip3 can gain execution through the download of visual basic files. |
| T1497.001 System Checks |
ToolAsyncRAT | AsyncRAT can identify strings such as Virtual, vmware, or VirtualBox to detect virtualized environments. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSnip3 | Snip3 can create a VBS file in startup to persist after system restarts. |
| T1564.003 Hidden Window |
ToolAsyncRAT | AsyncRAT can hide the execution of scheduled tasks using `ProcessWindowStyle.Hidden`. |
| T1566.001 Spearphishing Attachment |
MalwareSnip3 | Snip3 has been delivered to victims through malicious e-mail attachments. |
| T1566.002 Spearphishing Link |
MalwareSnip3 | Snip3 has been delivered to victims through e-mail links to malicious files. |
| T1566.002 Spearphishing Link |
GroupTA2541 | TA2541 has used spearphishing e-mails with malicious links to deliver malware. |
| T1622 Debugger Evasion |
ToolAsyncRAT | AsyncRAT can use the `CheckRemoteDebuggerPresent` function to detect the presence of a debugger. |
| T1680 Local Storage Discovery |
ToolAsyncRAT | AsyncRAT can check the disk size through the values obtained with `DeviceInfo.` |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.