Hayashi, K. (2005, August 18). Backdoor.Darkmoon. Retrieved February 23, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwarePoisonIvy | PoisonIvy creates a backdoor through which remote attackers can steal system information. |
| T1010 Application Window Discovery |
MalwarePoisonIvy | PoisonIvy captures window titles. |
| T1014 Rootkit |
MalwarePoisonIvy | PoisonIvy starts a rootkit from a malicious file dropped to disk. |
| T1027 Obfuscated Files or Information |
MalwarePoisonIvy | PoisonIvy hides any strings related to its own indicators of compromise. |
| T1055.001 Dynamic-link Library Injection |
MalwarePoisonIvy | PoisonIvy can inject a malicious DLL into a process. |
| T1056.001 Keylogging |
MalwarePoisonIvy | PoisonIvy contains a keylogger. |
| T1059.003 Windows Command Shell |
MalwarePoisonIvy | PoisonIvy creates a backdoor through which remote attackers can open a command-line interface. |
| T1074.001 Local Data Staging |
MalwarePoisonIvy | PoisonIvy stages collected data in a text file. |
| T1105 Ingress Tool Transfer |
MalwarePoisonIvy | PoisonIvy creates a backdoor through which remote attackers can upload files. |
| T1112 Modify Registry |
MalwarePoisonIvy | PoisonIvy creates a Registry subkey that registers a new system device. |
| T1543.003 Windows Service |
MalwarePoisonIvy | PoisonIvy creates a Registry subkey that registers a new service. PoisonIvy also creates a Registry entry modifying the Logical Disk Manager service to point to a malicious DLL dropped to disk. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePoisonIvy | PoisonIvy creates run key Registry entries pointing to a malicious executable dropped to disk. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.