ATT&CKReferencesSymantec Darkmoon Aug 2005

Symantec Darkmoon Aug 2005

Hayashi, K. (2005, August 18). Backdoor.Darkmoon. Retrieved February 23, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarePoisonIvy

PoisonIvy creates a backdoor through which remote attackers can steal system information.

T1010
Application Window Discovery
MalwarePoisonIvy

PoisonIvy captures window titles.

T1014
Rootkit
MalwarePoisonIvy

PoisonIvy starts a rootkit from a malicious file dropped to disk.

T1027
Obfuscated Files or Information
MalwarePoisonIvy

PoisonIvy hides any strings related to its own indicators of compromise.

T1055.001
Dynamic-link Library Injection
MalwarePoisonIvy

PoisonIvy can inject a malicious DLL into a process.

T1056.001
Keylogging
MalwarePoisonIvy

PoisonIvy contains a keylogger.

T1059.003
Windows Command Shell
MalwarePoisonIvy

PoisonIvy creates a backdoor through which remote attackers can open a command-line interface.

T1074.001
Local Data Staging
MalwarePoisonIvy

PoisonIvy stages collected data in a text file.

T1105
Ingress Tool Transfer
MalwarePoisonIvy

PoisonIvy creates a backdoor through which remote attackers can upload files.

T1112
Modify Registry
MalwarePoisonIvy

PoisonIvy creates a Registry subkey that registers a new system device.

T1543.003
Windows Service
MalwarePoisonIvy

PoisonIvy creates a Registry subkey that registers a new service. PoisonIvy also creates a Registry entry modifying the Logical Disk Manager service to point to a malicious DLL dropped to disk.

T1547.001
Registry Run Keys / Startup Folder
MalwarePoisonIvy

PoisonIvy creates run key Registry entries pointing to a malicious executable dropped to disk.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.