ATT&CKReferencesCiubotariu 2014

Ciubotariu 2014

Ciubotariu, M. (2014, January 23). Trojan.Zeroaccess.C Hidden in NTFS EA. Retrieved December 2, 2014.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

TechniqueUsed byProcedure example
T1564.004
NTFS File Attributes
MalwareZeroaccess

Some variants of the Zeroaccess Trojan have been known to store data in Extended Attributes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.