pngdowner

S0067

Malware.View on attack.mitre.org

About this malware

pngdowner is malware used by Putter Panda. It is a simple tool with limited functionality and no persistence mechanism, suggesting it is used only as a simple "download-and-
execute" utility.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1070.004
File Deletion

pngdowner deletes content from C2 communications that was saved to the user's temporary directory.

T1071.001
Web Protocols

pngdowner uses HTTP for command and control.

T1552.001
Credentials In Files

If an initial connectivity check fails, pngdowner attempts to extract proxy details and credentials from Windows Protected Storage and from the IE Credentials Store. This allows the adversary to use the proxy credentials for subsequent requests if they enable outbound HTTP access.

Groups that use it1

Campaigns0

None recorded.

References1

  1. CrowdStrike Putter Panda Open source
    Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.