US-CERT. (2018, February 05). Malware Analysis Report (MAR) - 10135536-F. Retrieved June 11, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareHARDRAIN | HARDRAIN uses cmd.exe to execute |
| T1090 Proxy |
MalwareHARDRAIN | HARDRAIN uses the command |
| T1571 Non-Standard Port |
MalwareHARDRAIN | HARDRAIN binds and listens on port 443 with a FakeTLS method. |
| T1686.003 Windows Host Firewall |
MalwareHARDRAIN | HARDRAIN opens the Windows Firewall to modify incoming connections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.