SentinelLabs. (2022, September 22). Metador Technical Appendix. Retrieved April 4, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareMafalda | Mafalda can dump password hashes from `LSASS.exe`. |
| T1005 Data from Local System |
MalwaremetaMain | metaMain can collect files and system information from a compromised host. |
| T1012 Query Registry |
MalwareMafalda | Mafalda can enumerate Registry keys with all subkeys and values. |
| T1027.013 Encrypted/Encoded File |
MalwaremetaMain | metaMain's module file has been encrypted via XOR. |
| T1033 System Owner/User Discovery |
MalwareMafalda | Mafalda can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwaremetaMain | metaMain can collect the username from a compromised host. |
| T1041 Exfiltration Over C2 Channel |
MalwaremetaMain | metaMain can upload collected files and data to its C2 server. |
| T1056 Input Capture |
MalwaremetaMain | metaMain can log mouse events. |
| T1056 Input Capture |
MalwareMafalda | Mafalda can conduct mouse event logging. |
| T1056.001 Keylogging |
MalwaremetaMain | metaMain has the ability to log keyboard events. |
| T1057 Process Discovery |
MalwaremetaMain | metaMain can enumerate the processes that run on the platform. |
| T1059.001 PowerShell |
MalwareMafalda | Mafalda can execute PowerShell commands on a compromised machine. |
| T1059.003 Windows Command Shell |
MalwareMafalda | Mafalda can execute shell commands using `cmd.exe`. |
| T1070.004 File Deletion |
MalwaremetaMain | metaMain has deleted collected items after uploading the content to its C2 server. |
| T1070.006 Timestomp |
MalwaremetaMain | metaMain can change the `CreationTime`, `LastAccessTime`, and `LastWriteTime` file time attributes when executed with `SYSTEM` privileges. |
| T1071.001 Web Protocols |
MalwaremetaMain | metaMain can use HTTP for C2 communications. |
| T1074.001 Local Data Staging |
MalwaremetaMain | metaMain has stored the collected system files in a working directory. |
| T1082 System Information Discovery |
MalwareMafalda | Mafalda can collect the computer name of a compromised host. |
| T1082 System Information Discovery |
MalwaremetaMain | metaMain can collect the computer name from a compromised host. |
| T1083 File and Directory Discovery |
MalwaremetaMain | metaMain can recursively enumerate files in an operator-provided directory. |
| T1090.001 Internal Proxy |
MalwareMafalda | Mafalda can create a named pipe to listen for and send data to a named pipe-based C2 server. |
| T1090.001 Internal Proxy |
MalwaremetaMain | metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server. |
| T1095 Non-Application Layer Protocol |
MalwaremetaMain | metaMain can establish an indirect and raw TCP socket-based connection to the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareMafalda | Mafalda can download additional files onto the compromised host. |
| T1105 Ingress Tool Transfer |
MalwaremetaMain | metaMain can download files onto compromised systems. |
| T1106 Native API |
MalwaremetaMain | metaMain can execute an operator-provided Windows command by leveraging functions such as `WinExec`, `WriteFile`, and `ReadFile`. |
| T1112 Modify Registry |
MalwaremetaMain | metaMain can write the process ID of a target process into the `HKEY_LOCAL_MACHINE\SOFTWARE\DDE\tpid` Registry value as part of its reflective loading activity. |
| T1112 Modify Registry |
MalwareMafalda | Mafalda can manipulate the system registry on a compromised host. |
| T1113 Screen Capture |
MalwaremetaMain | metaMain can take and save screenshots. |
| T1132.001 Standard Encoding |
MalwareMafalda | Mafalda can encode data using Base64 prior to exfiltration. |
| T1133 External Remote Services |
MalwareMafalda | Mafalda can establish an SSH connection from a compromised host to a server. |
| T1134 Access Token Manipulation |
MalwareMafalda | Mafalda can use `AdjustTokenPrivileges()` to elevate privileges. |
| T1134.003 Make and Impersonate Token |
MalwareMafalda | Mafalda can create a token for a different user. |
| T1205.001 Port Knocking |
MalwareMafalda | Mafalda can use port-knocking to authenticate itself to another implant called Cryshell to establish an indirect connection to the C2 server. |
| T1497.003 Time Based Checks |
MalwaremetaMain | metaMain has delayed execution for five to six minutes during its persistence establishment process. |
| T1518.001 Security Software Discovery |
MalwareMafalda | Mafalda can search for a variety of security software programs, EDR systems, and malware analysis tools. |
| T1569.002 Service Execution |
MalwareMafalda | Mafalda can create a remote service, let it run once, and then delete it. |
| T1573.001 Symmetric Cryptography |
MalwaremetaMain | metaMain can encrypt the data that it sends and receives from the C2 server using an RC4 encryption algorithm. |
| T1574.001 DLL |
MalwaremetaMain | metaMain can support an HKCMD sideloading start method. |
| T1622 Debugger Evasion |
MalwareMafalda | Mafalda can search for debugging tools on a compromised host. |
| T1680 Local Storage Discovery |
MalwareMafalda | Mafalda can enumerate all drives on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.