Reynolds, J.. (2016, September 14). H1N1: Technical analysis reveals new capabilities – part 2. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareH1N1 | H1N1 kills and disables services by using cmd.exe. |
| T1080 Taint Shared Content |
MalwareH1N1 | H1N1 has functionality to copy itself to network shares. |
| T1091 Replication Through Removable Media |
MalwareH1N1 | H1N1 has functionality to copy itself to removable media. |
| T1105 Ingress Tool Transfer |
MalwareH1N1 | H1N1 contains a command to download and execute a file from a remotely hosted URL using WinINet HTTP requests. |
| T1132 Data Encoding |
MalwareH1N1 | H1N1 obfuscates C2 traffic with an altered version of base64. |
| T1490 Inhibit System Recovery |
MalwareH1N1 | H1N1 disable recovery options and deletes shadow copies from the victim. |
| T1548.002 Bypass User Account Control |
MalwareH1N1 | H1N1 bypasses user access control by using a DLL hijacking vulnerability in the Windows Update Standalone Installer (wusa.exe). |
| T1555.003 Credentials from Web Browsers |
MalwareH1N1 | H1N1 dumps usernames and passwords from Firefox, Internet Explorer, and Outlook. |
| T1573.001 Symmetric Cryptography |
MalwareH1N1 | H1N1 encrypts C2 traffic using an RC4 key. |
| T1685 Disable or Modify Tools |
MalwareH1N1 | H1N1 kills and disables services for Windows Security Center, and Windows Defender. |
| T1686.003 Windows Host Firewall |
MalwareH1N1 | H1N1 kills and disables services for Windows Firewall. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.