Computer Incident Response Center Luxembourg. (2013, March 29). Analysis of a PlugX variant. Retrieved November 5, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwarePlugX | PlugX can enumerate and query for information contained within the Windows Registry. |
| T1049 System Network Connections Discovery |
MalwarePlugX | PlugX has a module for enumerating TCP and UDP network connections and associated processes using the |
| T1056.001 Keylogging |
MalwarePlugX | PlugX has a module for capturing keystrokes per process including window titles. |
| T1057 Process Discovery |
MalwarePlugX | PlugX has a module to list the processes running on a machine. |
| T1059.003 Windows Command Shell |
MalwarePlugX | PlugX allows actors to spawn a reverse shell on a victim. |
| T1083 File and Directory Discovery |
MalwarePlugX | PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution. |
| T1105 Ingress Tool Transfer |
MalwarePlugX | PlugX has a module to download and execute files on the compromised machine. |
| T1112 Modify Registry |
MalwarePlugX | PlugX has a module to create, delete, or modify Registry keys. |
| T1113 Screen Capture |
MalwarePlugX | PlugX allows the operator to capture screenshots. |
| T1135 Network Share Discovery |
MalwarePlugX | PlugX has a module to enumerate network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePlugX | PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory. |
| T1543.003 Windows Service |
MalwarePlugX | PlugX can be added as a service to establish persistence. PlugX also has a module to change service configurations as well as start, control, and delete services. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePlugX | PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.