Cap, P., et al. (2017, January 25). Detecting threat actors in recent German industrial attacks with Windows Defender ATP. Retrieved February 8, 2017.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareWinnti for Windows | A Winnti for Windows implant file was named ASPNET_FILTER.DLL, mimicking the legitimate ASP.NET ISAPI filter DLL with the same name. |
| T1218.011 Rundll32 |
MalwareWinnti for Windows | The Winnti for Windows installer loads a DLL using rundll32. |
| T1543.003 Windows Service |
MalwareWinnti for Windows | Winnti for Windows sets its DLL file as a new service in the Registry to establish persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.