Falcone, R. and Wartell, R.. (2015, July 27). Observations on CVE-2015-3113, Prior Zero-Days and the Pirpi Payload. Retrieved January 22, 2016.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
MalwareSHOTPUT | SHOTPUT has a command to list all servers in the domain, as well as one to locate domain controllers on a domain. |
| T1027 Obfuscated Files or Information |
MalwareSHOTPUT | SHOTPUT is obscured using XOR encoding and appended to a valid GIF file. |
| T1049 System Network Connections Discovery |
MalwareSHOTPUT | |
| T1057 Process Discovery |
MalwareSHOTPUT | SHOTPUT has a command to obtain a process listing. |
| T1083 File and Directory Discovery |
MalwareSHOTPUT | SHOTPUT has a command to obtain a directory listing. |
| T1087.001 Local Account |
MalwareSHOTPUT | SHOTPUT has a command to retrieve information about connected users. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.