NCSC GCHQ. (2022, January 27). Small Sieve Malware Analysis Report. Retrieved August 22, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareSmall Sieve | Small Sieve can obtain the IP address of a victim host. |
| T1027 Obfuscated Files or Information |
MalwareSmall Sieve | Small Sieve has the ability to use a custom hex byte swapping encoding scheme combined with an obfuscated Base64 function to protect program strings and Telegram credentials. |
| T1033 System Owner/User Discovery |
MalwareSmall Sieve | Small Sieve can obtain the id of a logged in user. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSmall Sieve | Small Sieve can use variations of Microsoft and Outlook spellings, such as "Microsift", in its file names to avoid detection. |
| T1059.003 Windows Command Shell |
MalwareSmall Sieve | Small Sieve can use `cmd.exe` to execute commands on a victim's system. |
| T1059.006 Python |
MalwareSmall Sieve | Small Sieve can use Python scripts to execute commands. |
| T1102.002 Bidirectional Communication |
MalwareSmall Sieve | Small Sieve has the ability to use the Telegram Bot API from Telegram Messenger to send and receive messages. |
| T1105 Ingress Tool Transfer |
MalwareSmall Sieve | Small Sieve has the ability to download files. |
| T1132.002 Non-Standard Encoding |
MalwareSmall Sieve | Small Sieve can use a custom hex byte swapping encoding scheme to obfuscate tasking traffic. |
| T1480 Execution Guardrails |
MalwareSmall Sieve | Small Sieve can only execute correctly if the word `Platypus` is passed to it on the command line. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSmall Sieve | Small Sieve has the ability to add itself to `HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OutlookMicrosift` for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.