Malware.View on attack.mitre.org
4H RAT is malware that has been used by Putter Panda since at least 2007.
| Technique | Procedure example |
|---|---|
| T1057 Process Discovery |
4H RAT has the capability to obtain a listing of running processes (including loaded modules). |
| T1059.003 Windows Command Shell |
4H RAT has the capability to create a remote shell. |
| T1071.001 Web Protocols |
4H RAT uses HTTP for command and control. |
| T1082 System Information Discovery |
4H RAT sends an OS version identifier in its beacons. |
| T1083 File and Directory Discovery |
4H RAT has the capability to obtain file and directory listings. |
| T1573.001 Symmetric Cryptography |
4H RAT obfuscates C2 communication using a 1-byte XOR with the key 0xBE. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.