ATT&CKReferencesPalo Alto CVE-2015-3113 July 2015

Palo Alto CVE-2015-3113 July 2015

Falcone, R. and Wartell, R.. (2015, July 27). Observations on CVE-2015-3113, Prior Zero-Days and the Pirpi Payload. Retrieved January 22, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareSHOTPUT

SHOTPUT has a command to list all servers in the domain, as well as one to locate domain controllers on a domain.

T1027
Obfuscated Files or Information
MalwareSHOTPUT

SHOTPUT is obscured using XOR encoding and appended to a valid GIF file.

T1049
System Network Connections Discovery
MalwareSHOTPUT

SHOTPUT uses netstat to list TCP connection status.

T1057
Process Discovery
MalwareSHOTPUT

SHOTPUT has a command to obtain a process listing.

T1083
File and Directory Discovery
MalwareSHOTPUT

SHOTPUT has a command to obtain a directory listing.

T1087.001
Local Account
MalwareSHOTPUT

SHOTPUT has a command to retrieve information about connected users.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.