ATT&CKReferencesJPCert TSCookie March 2018

JPCert TSCookie March 2018

Tomonaga, S. (2018, March 6). Malware “TSCookie”. Retrieved May 6, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareTSCookie

TSCookie has the ability to identify the IP of the infected host.

T1057
Process Discovery
MalwareTSCookie

TSCookie has the ability to list processes on the infected host.

T1059.003
Windows Command Shell
MalwareTSCookie

TSCookie has the ability to execute shell commands on the infected host.

T1071.001
Web Protocols
MalwareTSCookie

TSCookie can multiple protocols including HTTP and HTTPS in communication with command and control (C2) servers.

T1083
File and Directory Discovery
MalwareTSCookie

TSCookie has the ability to discover drive information on the infected host.

T1105
Ingress Tool Transfer
MalwareTSCookie

TSCookie has the ability to upload and download files to and from the infected host.

T1140
Deobfuscate/Decode Files or Information
MalwareTSCookie

TSCookie has the ability to decrypt, load, and execute a DLL and its resources.

T1204.001
Malicious Link
MalwareTSCookie

TSCookie has been executed via malicious links embedded in e-mails spoofing the Ministries of Education, Culture, Sports, Science and Technology of Japan.

T1555.003
Credentials from Web Browsers
MalwareTSCookie

TSCookie has the ability to steal saved passwords from the Internet Explorer, Edge, Firefox, and Chrome browsers.

T1573.001
Symmetric Cryptography
MalwareTSCookie

TSCookie has encrypted network communications with RC4.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.