Lorber, N. (2021, May 7). Revealing the Snip3 Crypter, a Highly Evasive RAT Loader. Retrieved September 13, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareSnip3 | Snip3 has the ability to obfuscate strings using XOR encryption. |
| T1027.001 Binary Padding |
MalwareSnip3 | Snip3 can obfuscate strings using junk Chinese characters. |
| T1047 Windows Management Instrumentation |
MalwareSnip3 | Snip3 can query the WMI class `Win32_ComputerSystem` to gather information. |
| T1055.012 Process Hollowing |
MalwareSnip3 | Snip3 can use RunPE to execute malicious payloads within a hollowed Windows process. |
| T1059.001 PowerShell |
MalwareSnip3 | Snip3 can use a PowerShell script for second-stage execution. |
| T1059.005 Visual Basic |
MalwareSnip3 | Snip3 can use visual basic scripts for first-stage execution. |
| T1082 System Information Discovery |
MalwareSnip3 | Snip3 has the ability to query `Win32_ComputerSystem` for system information. |
| T1102 Web Service |
MalwareSnip3 | Snip3 can download additional payloads from web services including Pastebin and top4top. |
| T1104 Multi-Stage Channels |
MalwareSnip3 | Snip3 can download and execute additional payloads and modules over separate communication channels. |
| T1105 Ingress Tool Transfer |
MalwareSnip3 | Snip3 can download additional payloads to compromised systems. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSnip3 | Snip3 can decode its second-stage PowerShell script prior to execution. |
| T1204.002 Malicious File |
MalwareSnip3 | Snip3 can gain execution through the download of visual basic files. |
| T1497.001 System Checks |
MalwareSnip3 | Snip3 has the ability to detect Windows Sandbox, VMWare, or VirtualBox by querying `Win32_ComputerSystem` to extract the `Manufacturer` string. |
| T1497.003 Time Based Checks |
MalwareSnip3 | Snip3 can execute `WScript.Sleep` to delay execution of its second stage. |
| T1564.003 Hidden Window |
MalwareSnip3 | Snip3 can execute PowerShell scripts in a hidden window. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.