Pantazopoulos, N. (2018, April 17). Decoding network data from a Gh0st RAT variant. Retrieved November 2, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059 Command and Scripting Interpreter |
Malwaregh0st RAT | gh0st RAT is able to open a remote shell to execute commands. |
| T1105 Ingress Tool Transfer |
Malwaregh0st RAT | gh0st RAT can download files to the victim’s machine. |
| T1113 Screen Capture |
Malwaregh0st RAT | gh0st RAT can capture the victim’s screen remotely. |
| T1543.003 Windows Service |
Malwaregh0st RAT | gh0st RAT can create a new service to establish persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
Malwaregh0st RAT | gh0st RAT has added a Registry Run key to establish persistence. |
| T1573.001 Symmetric Cryptography |
Malwaregh0st RAT | gh0st RAT uses RC4 and XOR to encrypt C2 traffic. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.