ATT&CKReferencesMicrosoft Winnti Jan 2017

Microsoft Winnti Jan 2017

Cap, P., et al. (2017, January 25). Detecting threat actors in recent German industrial attacks with Windows Defender ATP. Retrieved February 8, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareWinnti for Windows

A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name.

T1218.011
Rundll32
MalwareWinnti for Windows

The Winnti for Windows installer loads a DLL using rundll32.

T1543.003
Windows Service
MalwareWinnti for Windows

Winnti for Windows sets its DLL file as a new service in the Registry to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.