ATT&CKReferencesSecurelist Dtrack

Securelist Dtrack

Konstantin Zykov. (2019, September 23). Hello! My name is Dtrack. Retrieved January 20, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareDtrack

Dtrack can collect the host's IP addresses using the ipconfig command.

T1027.009
Embedded Payloads
MalwareDtrack

Dtrack has used a dropper that embeds an encrypted payload as extra data.

T1049
System Network Connections Discovery
MalwareDtrack

Dtrack can collect network and active connection information.

T1055.012
Process Hollowing
MalwareDtrack

Dtrack has used process hollowing shellcode to target a predefined list of processes from %SYSTEM32%.

T1056.001
Keylogging
MalwareDtrack

Dtrack’s dropper contains a keylogging executable.

T1057
Process Discovery
MalwareDtrack

Dtrack’s dropper can list all running processes.

T1070.004
File Deletion
MalwareDtrack

Dtrack can remove its persistence and delete itself.

T1074.001
Local Data Staging
MalwareDtrack

Dtrack can save collected data to disk, different file formats, and network shares.

T1082
System Information Discovery
MalwareDtrack

Dtrack can collect the victim's computer name, hostname and adapter information to create a unique identifier.

T1083
File and Directory Discovery
MalwareDtrack

Dtrack can list files on available disk volumes.

T1105
Ingress Tool Transfer
MalwareDtrack

Dtrack’s can download and upload a file to the victim’s computer.

T1140
Deobfuscate/Decode Files or Information
MalwareDtrack

Dtrack has used a decryption routine that is part of an executable physical patch.

T1217
Browser Information Discovery
MalwareDtrack

Dtrack can retrieve browser history.

T1547
Boot or Logon Autostart Execution
MalwareDtrack

Dtrack’s RAT makes a persistent target file with auto execution on the host start.

T1560
Archive Collected Data
MalwareDtrack

Dtrack packs collected data into a password protected archive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.