Lambert, T. (2020, January 29). Intro to Netwire. Retrieved January 7, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwareNETWIRE | NETWIRE can discover and close windows on controlled systems. |
| T1016 System Network Configuration Discovery |
MalwareNETWIRE | NETWIRE can collect the IP address of a compromised host. |
| T1027.002 Software Packing |
MalwareNETWIRE | NETWIRE has used .NET packer tools to evade detection. |
| T1027.011 Fileless Storage |
MalwareNETWIRE | NETWIRE can store its configuration information in the Registry under `HKCU:\Software\Netwire`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareNETWIRE | NETWIRE has masqueraded as legitimate software including TeamViewer and macOS Finder. |
| T1053.003 Cron |
MalwareNETWIRE | NETWIRE can use crontabs to establish persistence. |
| T1055 Process Injection |
MalwareNETWIRE | NETWIRE can inject code into system processes including notepad.exe, svchost.exe, and vbc.exe. |
| T1055.012 Process Hollowing |
MalwareNETWIRE | The NETWIRE payload has been injected into benign Microsoft executables via process hollowing. |
| T1056.001 Keylogging |
MalwareNETWIRE | NETWIRE can perform keylogging. |
| T1059.003 Windows Command Shell |
MalwareNETWIRE | NETWIRE can issue commands using cmd.exe. |
| T1059.004 Unix Shell |
MalwareNETWIRE | NETWIRE has the ability to use |
| T1071.001 Web Protocols |
MalwareNETWIRE | NETWIRE has the ability to communicate over HTTP. |
| T1090 Proxy |
MalwareNETWIRE | NETWIRE can implement use of proxies to pivot traffic. |
| T1095 Non-Application Layer Protocol |
MalwareNETWIRE | NETWIRE can use TCP in C2 communications. |
| T1112 Modify Registry |
MalwareNETWIRE | NETWIRE can modify the Registry to store its configuration information. |
| T1113 Screen Capture |
MalwareNETWIRE | NETWIRE can capture the victim's screen. |
| T1119 Automated Collection |
MalwareNETWIRE | NETWIRE can automatically archive collected data. |
| T1543.001 Launch Agent |
MalwareNETWIRE | NETWIRE can use launch agents for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareNETWIRE | NETWIRE creates a Registry start-up entry to establish persistence. |
| T1547.013 XDG Autostart Entries |
MalwareNETWIRE | NETWIRE can use XDG Autostart Entries to establish persistence on Linux systems. |
| T1547.015 Login Items |
MalwareNETWIRE | NETWIRE can persist via startup options for Login items. |
| T1555 Credentials from Password Stores |
MalwareNETWIRE | NETWIRE can retrieve passwords from messaging and mail client applications. |
| T1555.003 Credentials from Web Browsers |
MalwareNETWIRE | NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome. |
| T1560 Archive Collected Data |
MalwareNETWIRE | NETWIRE has the ability to compress archived screenshots. |
| T1564.001 Hidden Files and Directories |
MalwareNETWIRE | NETWIRE can copy itself to and launch itself from hidden folders. |
| T1573 Encrypted Channel |
MalwareNETWIRE | NETWIRE can encrypt C2 communications. |
| T1573.001 Symmetric Cryptography |
MalwareNETWIRE | NETWIRE can use AES encryption for C2 data transferred. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.