Kaspersky Lab. (2017, August). ShadowPad: popular server management software hit in supply chain attack. Retrieved March 22, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareShadowPad | ShadowPad has collected the domain name of the victim system. |
| T1027.011 Fileless Storage |
MalwareShadowPad | ShadowPad maintains a configuration block and virtual file system in the Registry. |
| T1033 System Owner/User Discovery |
MalwareShadowPad | ShadowPad has collected the username of the victim system. |
| T1055 Process Injection |
MalwareShadowPad | ShadowPad has injected an install module into a newly created process. |
| T1055.001 Dynamic-link Library Injection |
MalwareShadowPad | ShadowPad has injected a DLL into svchost.exe. |
| T1057 Process Discovery |
MalwareShadowPad | ShadowPad has collected the PID of a malicious process. |
| T1070 Indicator Removal |
MalwareShadowPad | ShadowPad has deleted arbitrary Registry values. |
| T1071.001 Web Protocols |
MalwareShadowPad | ShadowPad communicates over HTTP to retrieve a string that is decoded into a C2 server URL. |
| T1071.002 File Transfer Protocols |
MalwareShadowPad | ShadowPad has used FTP for C2 communications. |
| T1071.004 DNS |
MalwareShadowPad | ShadowPad has used DNS tunneling for C2 communications. |
| T1082 System Information Discovery |
MalwareShadowPad | ShadowPad has discovered system information including memory status, CPU frequency, and OS versions. |
| T1095 Non-Application Layer Protocol |
MalwareShadowPad | ShadowPad has used UDP for C2 communications. |
| T1112 Modify Registry |
MalwareShadowPad | ShadowPad can modify the Registry to store and maintain a configuration block and virtual file system. |
| T1124 System Time Discovery |
MalwareShadowPad | ShadowPad has collected the current date and time of the victim system. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareShadowPad | ShadowPad has decrypted a binary blob to start execution. |
| T1568.002 Domain Generation Algorithms |
MalwareShadowPad | ShadowPad uses a DGA that is based on the day of the month for C2 servers. |
| T1680 Local Storage Discovery |
MalwareShadowPad | ShadowPad has discovered system information including volume serial numbers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.