Maniath, S. and Kadam P. (2019, March 19). Dissecting a NETWIRE Phishing Campaign's Usage of Process Hollowing. Retrieved January 7, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareNETWIRE | NETWIRE has used a custom obfuscation algorithm to hide strings including Registry keys, APIs, and DLL names. |
| T1049 System Network Connections Discovery |
MalwareNETWIRE | NETWIRE can capture session logon details from a compromised host. |
| T1053.005 Scheduled Task |
MalwareNETWIRE | NETWIRE can create a scheduled task to establish persistence. |
| T1055.012 Process Hollowing |
MalwareNETWIRE | The NETWIRE payload has been injected into benign Microsoft executables via process hollowing. |
| T1056.001 Keylogging |
MalwareNETWIRE | NETWIRE can perform keylogging. |
| T1057 Process Discovery |
MalwareNETWIRE | NETWIRE can discover processes on compromised hosts. |
| T1059.001 PowerShell |
MalwareNETWIRE | The NETWIRE binary has been executed via PowerShell script. |
| T1059.005 Visual Basic |
MalwareNETWIRE | NETWIRE has been executed through use of VBScripts. |
| T1074.001 Local Data Staging |
MalwareNETWIRE | NETWIRE has the ability to write collected data to a file created in the |
| T1102 Web Service |
MalwareNETWIRE | NETWIRE has used web services including Paste.ee to host payloads. |
| T1105 Ingress Tool Transfer |
MalwareNETWIRE | NETWIRE can downloaded payloads from C2 to the compromised host. |
| T1106 Native API |
MalwareNETWIRE | NETWIRE can use Native API including |
| T1113 Screen Capture |
MalwareNETWIRE | NETWIRE can capture the victim's screen. |
| T1204.001 Malicious Link |
MalwareNETWIRE | NETWIRE has been executed through convincing victims into clicking malicious links. |
| T1204.001 Malicious Link |
GroupTA2541 | TA2541 has used malicious links to cloud and web services to gain execution on victim machines. |
| T1204.002 Malicious File |
MalwareNETWIRE | NETWIRE has been executed through luring victims into opening malicious documents. |
| T1555.003 Credentials from Web Browsers |
MalwareNETWIRE | NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome. |
| T1560.003 Archive via Custom Method |
MalwareNETWIRE | NETWIRE has used a custom encryption algorithm to encrypt collected data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.