Mis-Type

S0084

Malware.View on attack.mitre.org

About this malware

Mis-Type is a backdoor hybrid that was used in Operation Dust Storm by 2012.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1005
Data from Local System

Mis-Type has collected files and data from a compromised host.

T1008
Fallback Channels

Mis-Type first attempts to use a Base64-encoded network protocol over a raw TCP socket for C2, and if that method fails, falls back to a secondary HTTP-based protocol to communicate to an alternate C2 server.

T1016
System Network Configuration Discovery

Mis-Type may create a file containing the results of the command cmd.exe /c ipconfig /all.

T1033
System Owner/User Discovery

Mis-Type runs tests to determine the privilege level of the compromised user.

T1036.005
Match Legitimate Resource Name or Location

Mis-Type saves itself as a file named `msdtc.exe`, which is also the name of the legitimate Microsoft Distributed Transaction Coordinator service binary.

T1041
Exfiltration Over C2 Channel

Mis-Type has transmitted collected files and data to its C2 server.

T1055
Process Injection

Mis-Type has been injected directly into a running process, including `explorer.exe`.

T1059.003
Windows Command Shell

Mis-Type has used `cmd.exe` to run commands on a compromised host.

T1071.001
Web Protocols

Mis-Type network traffic can communicate over HTTP.

T1074.001
Local Data Staging

Mis-Type has temporarily stored collected information to the files `“%AppData%\{Unique Identifier}\HOSTRURKLSR”` and `“%AppData%\{Unique Identifier}\NEWERSSEMP”`.

T1082
System Information Discovery

The initial beacon packet for Mis-Type contains the operating system version and file system of the victim.

T1087.001
Local Account

Mis-Type may create a file containing the results of the command cmd.exe /c net user {Username}.

T1095
Non-Application Layer Protocol

Mis-Type network traffic can communicate over a raw socket.

T1105
Ingress Tool Transfer

Mis-Type has downloaded additional malware and files onto a compromised host.

T1106
Native API

Mis-Type has used Windows API calls, including `NetUserAdd` and `NetUserDel`.

View all 18 procedure examples

Groups that use it0

None recorded.

Campaigns1

References1

  1. Cylance Dust Storm Open source
    Gross, J. (2016, February 23). Operation Dust Storm. Retrieved December 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.