CISA. (2020, July 16). MAR-10296782-3.v1 – WELLMAIL. Retrieved September 29, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareWellMail | WellMail can exfiltrate files from the victim machine. |
| T1016 System Network Configuration Discovery |
MalwareWellMail | WellMail can identify the IP address of the victim system. |
| T1033 System Owner/User Discovery |
MalwareWellMail | WellMail can identify the current username on the victim system. |
| T1095 Non-Application Layer Protocol |
MalwareWellMail | WellMail can use TCP for C2 communications. |
| T1105 Ingress Tool Transfer |
MalwareWellMail | WellMail can receive data and executable scripts from C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWellMail | WellMail can decompress scripts received from C2. |
| T1560 Archive Collected Data |
MalwareWellMail | WellMail can archive files on the compromised host. |
| T1571 Non-Standard Port |
MalwareWellMail | WellMail has been observed using TCP port 25, without using SMTP, to leverage an open port for secure command and control communications. |
| T1573.002 Asymmetric Cryptography |
MalwareWellMail | WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.