ATT&CKReferencesSymantec Backdoor.Mivast

Symantec Backdoor.Mivast

Stama, D.. (2015, February 6). Backdoor.Mivast. Retrieved February 15, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1003.002
Security Account Manager
MalwareMivast

Mivast has the capability to gather NTLM password information.

T1059.003
Windows Command Shell
MalwareMivast

Mivast has the capability to open a remote shell and run basic commands.

T1105
Ingress Tool Transfer
MalwareMivast

Mivast has the capability to download and execute .exe files.

T1547.001
Registry Run Keys / Startup Folder
MalwareMivast

Mivast creates the following Registry entry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Micromedia.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.