ATT&CKReferencesProofpoint NETWIRE December 2020

Proofpoint NETWIRE December 2020

Proofpoint. (2020, December 2). Geofenced NetWire Campaigns. Retrieved January 7, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareNETWIRE

NETWIRE can collect the IP address of a compromised host.

T1056.001
Keylogging
MalwareNETWIRE

NETWIRE can perform keylogging.

T1059.003
Windows Command Shell
MalwareNETWIRE

NETWIRE can issue commands using cmd.exe.

T1059.004
Unix Shell
MalwareNETWIRE

NETWIRE has the ability to use /bin/bash and /bin/sh to execute commands.

T1059.005
Visual Basic
MalwareNETWIRE

NETWIRE has been executed through use of VBScripts.

T1071.001
Web Protocols
MalwareNETWIRE

NETWIRE has the ability to communicate over HTTP.

T1083
File and Directory Discovery
MalwareNETWIRE

NETWIRE has the ability to search for files on the compromised host.

T1105
Ingress Tool Transfer
MalwareNETWIRE

NETWIRE can downloaded payloads from C2 to the compromised host.

T1113
Screen Capture
MalwareNETWIRE

NETWIRE can capture the victim's screen.

T1204.002
Malicious File
MalwareNETWIRE

NETWIRE has been executed through luring victims into opening malicious documents.

T1547.001
Registry Run Keys / Startup Folder
MalwareNETWIRE

NETWIRE creates a Registry start-up entry to establish persistence.

T1555.003
Credentials from Web Browsers
MalwareNETWIRE

NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome.

T1566.001
Spearphishing Attachment
MalwareNETWIRE

NETWIRE has been spread via e-mail campaigns utilizing malicious attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.