Cylance SPEAR Team. (2017, February 9). Shell Crew Variants Continue to Fly Under Big AV’s Radar. Retrieved February 15, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareStreamEx | StreamEx obfuscates some commands by using statically programmed fragments of strings when starting a DLL. It also uses a one-byte xor against 0x91 to encode configuration data. |
| T1057 Process Discovery |
MalwareStreamEx | StreamEx has the ability to enumerate processes. |
| T1059.003 Windows Command Shell |
MalwareStreamEx | StreamEx has the ability to remotely execute commands. |
| T1082 System Information Discovery |
MalwareStreamEx | StreamEx has the ability to enumerate system information. |
| T1083 File and Directory Discovery |
MalwareStreamEx | StreamEx has the ability to enumerate drive types. |
| T1112 Modify Registry |
MalwareStreamEx | StreamEx has the ability to modify the Registry. |
| T1218.011 Rundll32 |
MalwareStreamEx | StreamEx uses rundll32 to call an exported function. |
| T1518.001 Security Software Discovery |
MalwareStreamEx | StreamEx has the ability to scan for security tools such as firewalls and antivirus tools. |
| T1543.003 Windows Service |
MalwareStreamEx | StreamEx establishes persistence by installing a new service pointing to its DLL and setting the service to auto-start. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.