Nesbit, B. and Ackerman, D. (2017, January). Malware Analysis Report - RawPOS Malware: Deconstructing an Intruder’s Toolkit. Retrieved October 4, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRawPOS | RawPOS dumps memory from specific processes on a victim system, parses the dumped files, and scrapes them for credit card data. |
| T1036.004 Masquerade Task or Service |
MalwareRawPOS | New services created by RawPOS are made to appear like legitimate Windows services, with names such as "Windows Management Help Service", "Microsoft Support", and "Windows Advanced Task Manager". |
| T1074.001 Local Data Staging |
MalwareRawPOS | Data captured by RawPOS is placed in a temporary file under a directory named "memdump". |
| T1543.003 Windows Service |
MalwareRawPOS | RawPOS installs itself as a service to maintain persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.