Grange, W. (2020, July 13). Anchor_dns malware goes cross platform. Retrieved September 10, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareAnchor | Anchor can determine the public IP and location of a compromised host. |
| T1021.002 SMB/Windows Admin Shares |
MalwareAnchor | Anchor can support windows execution via SMB shares. |
| T1053.003 Cron |
MalwareAnchor | Anchor can install itself as a cron job. |
| T1059.004 Unix Shell |
MalwareAnchor | Anchor can execute payloads via shell scripting. |
| T1071.004 DNS |
MalwareAnchor | Variants of Anchor can use DNS tunneling to communicate with C2. |
| T1082 System Information Discovery |
MalwareAnchor | Anchor can determine the hostname and linux version on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareAnchor | Anchor can download additional payloads. |
| T1569.002 Service Execution |
MalwareAnchor | Anchor can create and execute services to load its payload. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.