ATT&CKReferencesSecureworks MCMD July 2019

Secureworks MCMD July 2019

Secureworks. (2019, July 24). MCMD Malware Analysis. Retrieved August 13, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1005
Data from Local System
ToolMCMD

MCMD has the ability to upload files from an infected device.

T1027
Obfuscated Files or Information
ToolMCMD

MCMD can Base64 encode output strings prior to sending to C2.

T1036.005
Match Legitimate Resource Name or Location
ToolMCMD

MCMD has been named Readme.txt to appear legitimate.

T1053.005
Scheduled Task
ToolMCMD

MCMD can use scheduled tasks for persistence.

T1059.003
Windows Command Shell
ToolMCMD

MCMD can launch a console process (cmd.exe) with redirected standard input and output.

T1070.009
Clear Persistence
ToolMCMD

MCMD has the ability to remove set Registry Keys, including those used for persistence.

T1071.001
Web Protocols
ToolMCMD

MCMD can use HTTPS in communication with C2 web servers.

T1105
Ingress Tool Transfer
ToolMCMD

MCMD can upload additional files to a compromised host.

T1547.001
Registry Run Keys / Startup Folder
ToolMCMD

MCMD can use Registry Run Keys for persistence.

T1564.003
Hidden Window
ToolMCMD

MCMD can modify processes to prevent them from being visible on the desktop.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.