ATT&CKReferencesThreatStream Evasion Analysis

ThreatStream Evasion Analysis

Shelmire, A.. (2015, July 6). Evasive Maneuvers. Retrieved January 22, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareHTTPBrowser

HTTPBrowser has used HTTP and HTTPS for command and control.

T1071.004
DNS
MalwareHTTPBrowser

HTTPBrowser has used DNS for command and control.

T1543.003
Windows Service
MalwarehcdLoader

hcdLoader installs itself as a service for persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareHTTPBrowser

HTTPBrowser has established persistence by setting the HKCU\Software\Microsoft\Windows\CurrentVersion\Run key value for wdm to the path of the executable. It has also used the Registry entry HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run vpdn “%ALLUSERPROFILE%\%APPDATA%\vpdn\VPDN_LU.exe” to establish persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.