ATT&CKSoftwarehttpclient

httpclient

S0068

Malware.View on attack.mitre.org

About this malware

httpclient is malware used by Putter Panda. It is a simple tool that provides a limited range of functionality, suggesting it is likely used as a second-stage or supplementary/backup tool.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1059.003
Windows Command Shell

httpclient opens cmd.exe on the victim.

T1071.001
Web Protocols

httpclient uses HTTP for command and control.

T1573.001
Symmetric Cryptography

httpclient encrypts C2 content with XOR using a single byte, 0x12.

Groups that use it1

Campaigns0

None recorded.

References1

  1. CrowdStrike Putter Panda Open source
    Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.