DHS/CISA, Cyber National Mission Force. (2020, October 1). Malware Analysis Report (MAR) MAR-10303705-1.v1 – Remote Access Trojan: SLOTHFULMEDIA. Retrieved October 2, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has hashed a string containing system information prior to exfiltration via POST requests. |
| T1005 Data from Local System |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has uploaded files and information from victim machines. |
| T1007 System Service Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has the capability to enumerate services. |
| T1033 System Owner/User Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has collected the username from a victim machine. |
| T1036.004 Masquerade Task or Service |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has named a service it establishes on victim machines as "TaskFrame" to hide its malicious purpose. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has mimicked the names of known executables, such as mediaplayer.exe. |
| T1041 Exfiltration Over C2 Channel |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has sent system information to a C2 server via HTTP and HTTPS POST requests. |
| T1049 System Network Connections Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can enumerate open ports on a victim machine. |
| T1055 Process Injection |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can inject into running processes on a compromised host. |
| T1056.001 Keylogging |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has a keylogging capability. |
| T1057 Process Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has enumerated processes by ID, name, or privileges. |
| T1059.003 Windows Command Shell |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can open a command line to execute commands. |
| T1070.004 File Deletion |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has deleted itself and the 'index.dat' file on a compromised machine to remove recent Internet history from the system. |
| T1071.001 Web Protocols |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has used HTTP and HTTPS for C2 communications. |
| T1082 System Information Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has collected system name, OS version, adapter information, and memory usage from a victim machine. |
| T1083 File and Directory Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can enumerate files and directories. |
| T1105 Ingress Tool Transfer |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has downloaded files onto a victim machine. |
| T1112 Modify Registry |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can add, modify, and/or delete registry keys. It has changed the proxy configuration of a victim system by modifying the |
| T1113 Screen Capture |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has taken a screenshot of a victim's desktop, named it "Filter3.jpg", and stored it in the local directory. |
| T1489 Service Stop |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has the capability to stop processes and services. |
| T1543.003 Windows Service |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has created a service on victim machines named "TaskFrame" to establish persistence. |
| T1564.001 Hidden Files and Directories |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has been created with a hidden attribute to insure it's not visible to the victim. |
| T1569.002 Service Execution |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has the capability to start services. |
| T1680 Local Storage Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has collected disk information from a victim machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.