Chen, T. and Chen, Z. (2020, February 17). CLAMBLING - A New Backdoor Base On Dropbox. Retrieved November 12, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareClambling | Clambling has the ability to enumerate Registry keys, including |
| T1016 System Network Configuration Discovery |
MalwareClambling | Clambling can enumerate the IP address of a compromised machine. |
| T1033 System Owner/User Discovery |
MalwareClambling | Clambling can identify the username on a compromised host. |
| T1056.001 Keylogging |
MalwareClambling | Clambling can capture keystrokes on a compromised host. |
| T1082 System Information Discovery |
MalwareClambling | Clambling can discover the hostname, computer name, and Windows version of a targeted machine. |
| T1083 File and Directory Discovery |
MalwareClambling | Clambling can browse directories on a compromised host. |
| T1102.002 Bidirectional Communication |
MalwareClambling | Clambling can use Dropbox to download malicious payloads, send commands, and receive information. |
| T1115 Clipboard Data |
MalwareClambling | Clambling has the ability to capture and store clipboard data. |
| T1125 Video Capture |
MalwareClambling | Clambling can record screen content in AVI format. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareClambling | Clambling can deobfuscate its payload prior to execution. |
| T1543.003 Windows Service |
MalwareClambling | Clambling can register itself as a system service to gain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareClambling | Clambling can establish persistence by adding a Registry run key. |
| T1548.002 Bypass User Account Control |
MalwareClambling | Clambling has the ability to bypass UAC using a `passuac.dll` file. |
| T1567.002 Exfiltration to Cloud Storage |
MalwareClambling | Clambling can send files from a victim's machine to Dropbox. |
| T1574.001 DLL |
MalwareClambling | Clambling can store a file named `mpsvc.dll`, which opens a malicious `mpsvc.mui` file, in the same folder as the legitimate Microsoft executable `MsMpEng.exe` to gain execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.