ATT&CKReferencesCIRCL PlugX March 2013

CIRCL PlugX March 2013

Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1012
Query Registry
MalwarePlugX

PlugX can enumerate and query for information contained within the Windows Registry.

T1049
System Network Connections Discovery
MalwarePlugX

PlugX has a module for enumerating TCP and UDP network connections and associated processes using the netstat command.

T1056.001
Keylogging
MalwarePlugX

PlugX has a module for capturing keystrokes per process including window titles.

T1057
Process Discovery
MalwarePlugX

PlugX has a module to list the processes running on a machine.

T1059.003
Windows Command Shell
MalwarePlugX

PlugX allows actors to spawn a reverse shell on a victim.

T1083
File and Directory Discovery
MalwarePlugX

PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution.

T1105
Ingress Tool Transfer
MalwarePlugX

PlugX has a module to download and execute files on the compromised machine.

T1112
Modify Registry
MalwarePlugX

PlugX has a module to create, delete, or modify Registry keys.

T1113
Screen Capture
MalwarePlugX

PlugX allows the operator to capture screenshots.

T1135
Network Share Discovery
MalwarePlugX

PlugX has a module to enumerate network shares.

T1140
Deobfuscate/Decode Files or Information
MalwarePlugX

PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory.

T1543.003
Windows Service
MalwarePlugX

PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services.

T1547.001
Registry Run Keys / Startup Folder
MalwarePlugX

PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.