Shevchenko, S.. (2008, November 30). Agent.btz - A Threat That Hit Pentagon. Retrieved April 8, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareAgent.btz | Agent.btz collects the network adapter’s IP and MAC address as well as IP addresses of the network adapter’s default gateway, primary/secondary WINS, DHCP, and DNS servers, and saves them into a log file. |
| T1033 System Owner/User Discovery |
MalwareAgent.btz | Agent.btz obtains the victim username and saves it to a file. |
| T1091 Replication Through Removable Media |
MalwareAgent.btz | Agent.btz drops itself onto removable media devices and creates an autorun.inf file with an instruction to run that file. When the device is inserted into another system, it opens autorun.inf and loads the malware. |
| T1105 Ingress Tool Transfer |
MalwareAgent.btz | Agent.btz attempts to download an encrypted binary from a specified domain. |
| T1560.003 Archive via Custom Method |
MalwareAgent.btz | Agent.btz saves system information into an XML file that is then XOR-encoded. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.