ATT&CKReferencesJPCert PLEAD Downloader June 2018

JPCert PLEAD Downloader June 2018

Tomonaga, S. (2018, June 8). PLEAD Downloader Used by BlackTech. Retrieved May 6, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwarePLEAD

PLEAD has the ability to execute shell commands on the compromised host.

T1071.001
Web Protocols
MalwarePLEAD

PLEAD has used HTTP for communications with command and control (C2) servers.

T1083
File and Directory Discovery
MalwarePLEAD

PLEAD has the ability to list drives and files on the compromised host.

T1090
Proxy
MalwarePLEAD

PLEAD has the ability to proxy network communications.

T1105
Ingress Tool Transfer
MalwarePLEAD

PLEAD has the ability to upload and download files to and from an infected host.

T1573.001
Symmetric Cryptography
MalwarePLEAD

PLEAD has used RC4 encryption to download modules.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.