Trusteer Fraud Prevention Center. (2010, October 7). Carberp Under the Hood of Carberp: Malware & Configuration Analysis. Retrieved July 15, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCarberp | Carberp has masqueraded as Windows system file names, as well as "chkntfs.exe" and "syscron.exe". |
| T1041 Exfiltration Over C2 Channel |
MalwareCarberp | Carberp has exfiltrated data via HTTP to already established C2 servers. |
| T1057 Process Discovery |
MalwareCarberp | Carberp has collected a list of running processes. |
| T1071.001 Web Protocols |
MalwareCarberp | Carberp has connected to C2 servers via HTTP. |
| T1105 Ingress Tool Transfer |
MalwareCarberp | Carberp can download and execute new plugins from the C2 server. |
| T1106 Native API |
MalwareCarberp | Carberp has used the NtQueryDirectoryFile and ZwQueryDirectoryFile functions to hide files and directories. |
| T1185 Browser Session Hijacking |
MalwareCarberp | Carberp has captured credentials when a user performs login through a SSL session. |
| T1564.001 Hidden Files and Directories |
MalwareCarberp | Carberp has created a hidden file in the Startup folder of the current user. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.