Tomonaga, S.. (2019, September 18). Malware Used by BlackTech after Network Intrusion. Retrieved May 6, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
MalwareTSCookie | TSCookie has the ability to inject code into the svchost.exe, iexplorer.exe, explorer.exe, and default browser processes. |
| T1071.001 Web Protocols |
MalwareTSCookie | TSCookie can multiple protocols including HTTP and HTTPS in communication with command and control (C2) servers. |
| T1090 Proxy |
MalwareTSCookie | TSCookie has the ability to proxy communications with command and control (C2) servers. |
| T1095 Non-Application Layer Protocol |
MalwareTSCookie | TSCookie can use ICMP to receive information on the destination server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.