ATT&CKReferencesTrend Micro Conficker

Trend Micro Conficker

Trend Micro. (2014, March 18). Conficker. Retrieved February 18, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareConficker

Conficker has obfuscated its code to prevent its removal from host machines.

T1091
Replication Through Removable Media
MalwareConficker

Conficker variants used the Windows AUTORUN feature to spread through USB propagation.

T1112
Modify Registry
MalwareConficker

Conficker adds keys to the Registry at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services and various other Registry locations.

T1124
System Time Discovery
MalwareConficker

Conficker uses the current UTC victim system date for domain generation and connects to time servers to determine the current date.

T1547.001
Registry Run Keys / Startup Folder
MalwareConficker

Conficker adds Registry Run keys to establish persistence.

T1568.002
Domain Generation Algorithms
MalwareConficker

Conficker has used a DGA that seeds with the current UTC victim system date to generate domains.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.