Vilkomir-Preisman, S. (2019, April 2). New ServHelper Variant Employs Excel 4.0 Macro to Drop Signed Payload. Retrieved September 16, 2024..
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupTA505 | TA505 has used base64 encoded PowerShell commands. |
| T1059.001 PowerShell |
GroupTA505 | TA505 has used PowerShell to download and execute malware and reconnaissance scripts. |
| T1059.003 Windows Command Shell |
MalwareServHelper | ServHelper can execute shell commands against cmd. |
| T1070.004 File Deletion |
MalwareServHelper | ServHelper has a module to delete itself from the infected machine. |
| T1105 Ingress Tool Transfer |
GroupTA505 | TA505 has downloaded additional malware to execute on victim systems. |
| T1105 Ingress Tool Transfer |
MalwareServHelper | ServHelper may download additional files to execute. |
| T1218.007 Msiexec |
GroupTA505 | TA505 has used |
| T1218.011 Rundll32 |
GroupTA505 | TA505 has leveraged |
| T1218.011 Rundll32 |
MalwareServHelper | ServHelper contains a module for downloading and executing DLLs that leverages |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareServHelper | ServHelper may attempt to establish persistence via the |
| T1553.002 Code Signing |
GroupTA505 | TA505 has signed payloads with code signing certificates from Thawte and Sectigo. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.