GReAT. (2017, August 15). ShadowPad in corporate networks. Retrieved March 22, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareShadowPad | ShadowPad has encrypted its payload, a virtual file system, and various files. |
| T1029 Scheduled Transfer |
MalwareShadowPad | ShadowPad has sent data back to C2 every 8 hours. |
| T1105 Ingress Tool Transfer |
MalwareShadowPad | ShadowPad has downloaded code from a C2 server. |
| T1132.002 Non-Standard Encoding |
MalwareShadowPad | ShadowPad has encoded data as readable Latin characters. |
| T1568.002 Domain Generation Algorithms |
MalwareShadowPad | ShadowPad uses a DGA that is based on the day of the month for C2 servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.