ATT&CKReferencesKaspersky ShadowPad Aug 2017

Kaspersky ShadowPad Aug 2017

Kaspersky Lab. (2017, August). ShadowPad: popular server management software hit in supply chain attack. Retrieved March 22, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareShadowPad

ShadowPad has collected the domain name of the victim system.

T1027.011
Fileless Storage
MalwareShadowPad

ShadowPad maintains a configuration block and virtual file system in the Registry.

T1033
System Owner/User Discovery
MalwareShadowPad

ShadowPad has collected the username of the victim system.

T1055
Process Injection
MalwareShadowPad

ShadowPad has injected an install module into a newly created process.

T1055.001
Dynamic-link Library Injection
MalwareShadowPad

ShadowPad has injected a DLL into svchost.exe.

T1057
Process Discovery
MalwareShadowPad

ShadowPad has collected the PID of a malicious process.

T1070
Indicator Removal
MalwareShadowPad

ShadowPad has deleted arbitrary Registry values.

T1071.001
Web Protocols
MalwareShadowPad

ShadowPad communicates over HTTP to retrieve a string that is decoded into a C2 server URL.

T1071.002
File Transfer Protocols
MalwareShadowPad

ShadowPad has used FTP for C2 communications.

T1071.004
DNS
MalwareShadowPad

ShadowPad has used DNS tunneling for C2 communications.

T1082
System Information Discovery
MalwareShadowPad

ShadowPad has discovered system information including memory status, CPU frequency, and OS versions.

T1095
Non-Application Layer Protocol
MalwareShadowPad

ShadowPad has used UDP for C2 communications.

T1112
Modify Registry
MalwareShadowPad

ShadowPad can modify the Registry to store and maintain a configuration block and virtual file system.

T1124
System Time Discovery
MalwareShadowPad

ShadowPad has collected the current date and time of the victim system.

T1140
Deobfuscate/Decode Files or Information
MalwareShadowPad

ShadowPad has decrypted a binary blob to start execution.

T1568.002
Domain Generation Algorithms
MalwareShadowPad

ShadowPad uses a DGA that is based on the day of the month for C2 servers.

T1680
Local Storage Discovery
MalwareShadowPad

ShadowPad has discovered system information including volume serial numbers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.