ATT&CKReferencesSANS Conficker

SANS Conficker

Burton, K. (n.d.). The Conficker Worm. Retrieved February 18, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
MalwareConficker

Conficker variants spread through NetBIOS share propagation.

T1046
Network Service Discovery
MalwareConficker

Conficker scans for other machines to infect.

T1091
Replication Through Removable Media
MalwareConficker

Conficker variants used the Windows AUTORUN feature to spread through USB propagation.

T1105
Ingress Tool Transfer
MalwareConficker

Conficker downloads an HTTP server to the infected machine.

T1112
Modify Registry
MalwareConficker

Conficker adds keys to the Registry at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services and various other Registry locations.

T1124
System Time Discovery
MalwareConficker

Conficker uses the current UTC victim system date for domain generation and connects to time servers to determine the current date.

T1210
Exploitation of Remote Services
MalwareConficker

Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request.

T1490
Inhibit System Recovery
MalwareConficker

Conficker resets system restore points and deletes backup files.

T1543.003
Windows Service
MalwareConficker

Conficker copies itself into the %systemroot%\system32 directory and registers as a service.

T1568.002
Domain Generation Algorithms
MalwareConficker

Conficker has used a DGA that seeds with the current UTC victim system date to generate domains.

T1685
Disable or Modify Tools
MalwareConficker

Conficker terminates various services related to system security and Windows.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.