Symantec Security Response. (2015, June 23). Dyre: Emerging threat on financial fraud landscape. Retrieved August 23, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055.001 Dynamic-link Library Injection |
MalwareDyre | Dyre injects into other processes to load modules. |
| T1071.001 Web Protocols |
MalwareDyre | Dyre uses HTTPS for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareDyre | Dyre has a command to download and executes additional files. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDyre | Dyre decrypts resources needed for targeting the victim. |
| T1497.001 System Checks |
MalwareDyre | Dyre can detect sandbox analysis environments by inspecting the process list and Registry. |
| T1543.003 Windows Service |
MalwareDyre | Dyre registers itself as a service by adding several Registry keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.