ATT&CKReferencesSymantec Pasam May 2012

Symantec Pasam May 2012

Mullaney, C. & Honda, H. (2012, May 4). Trojan.Pasam. Retrieved February 22, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve files.

T1057
Process Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve lists of running processes.

T1070.004
File Deletion
MalwarePasam

Pasam creates a backdoor through which remote attackers can delete files.

T1082
System Information Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve information like hostname.

T1083
File and Directory Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve lists of files.

T1105
Ingress Tool Transfer
MalwarePasam

Pasam creates a backdoor through which remote attackers can upload files.

T1547.008
LSASS Driver
MalwarePasam

Pasam establishes by infecting the Security Accounts Manager (SAM) DLL to load a malicious DLL dropped to disk.

T1680
Local Storage Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve information like free disk space.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.