ATT&CKReferencesTalos Micropsia June 2017

Talos Micropsia June 2017

Rascagneres, P., Mercer, W. (2017, June 19). Delphi Used To Score Against Palestine. Retrieved November 13, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareMicropsia

Micropsia obfuscates the configuration with a custom Base64 and XOR.

T1033
System Owner/User Discovery
MalwareMicropsia

Micropsia collects the username from the victim’s machine.

T1047
Windows Management Instrumentation
MalwareMicropsia

Micropsia searches for anti-virus software and firewall products installed on the victim’s machine using WMI.

T1071.001
Web Protocols
MalwareMicropsia

Micropsia uses HTTP and HTTPS for C2 network communications.

T1082
System Information Discovery
MalwareMicropsia

Micropsia gathers the hostname and OS version from the victim’s machine.

T1105
Ingress Tool Transfer
MalwareMicropsia

Micropsia can download and execute an executable from the C2 server.

T1518.001
Security Software Discovery
MalwareMicropsia

Micropsia searches for anti-virus software and firewall products installed on the victim’s machine using WMI.

T1547.009
Shortcut Modification
MalwareMicropsia

Micropsia creates a shortcut to maintain persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.