ATT&CKReferencesSymantec Linfo May 2012

Symantec Linfo May 2012

Zhou, R. (2012, May 15). Backdoor.Linfo. Retrieved February 23, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareLinfo

Linfo creates a backdoor through which remote attackers can obtain data from local systems.

T1008
Fallback Channels
MalwareLinfo

Linfo creates a backdoor through which remote attackers can change C2 servers.

T1029
Scheduled Transfer
MalwareLinfo

Linfo creates a backdoor through which remote attackers can change the frequency at which compromised hosts contact remote C2 infrastructure.

T1057
Process Discovery
MalwareLinfo

Linfo creates a backdoor through which remote attackers can retrieve a list of running processes.

T1059.003
Windows Command Shell
MalwareLinfo

Linfo creates a backdoor through which remote attackers can start a remote shell.

T1070.004
File Deletion
MalwareLinfo

Linfo creates a backdoor through which remote attackers can delete files.

T1082
System Information Discovery
MalwareLinfo

Linfo creates a backdoor through which remote attackers can retrieve system information.

T1083
File and Directory Discovery
MalwareLinfo

Linfo creates a backdoor through which remote attackers can list contents of drives and search for files.

T1105
Ingress Tool Transfer
MalwareLinfo

Linfo creates a backdoor through which remote attackers can download files onto compromised hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.