Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
CORESHELL obfuscates strings using a custom stream cipher. |
| T1027.016 Junk Code Insertion |
CORESHELL contains unused machine instructions in a likely attempt to hinder analysis. |
| T1071.001 Web Protocols |
CORESHELL can communicate over HTTP for C2. |
| T1071.003 Mail Protocols |
CORESHELL can communicate over SMTP and POP3 for C2. |
| T1082 System Information Discovery |
CORESHELL collects hostname and OS version data from the victim and sends the information to its C2 server. |
| T1105 Ingress Tool Transfer |
CORESHELL downloads another dropper from its C2 server. |
| T1132.001 Standard Encoding |
CORESHELL C2 messages are Base64-encoded. |
| T1218.011 Rundll32 |
CORESHELL is installed via execution of rundll32 with an export named "init" or "InitW." |
| T1547.001 Registry Run Keys / Startup Folder |
CORESHELL has established persistence by creating autostart extensibility point (ASEP) Registry entries in the Run key and other Registry keys, as well as by creating shortcuts in the Internet Explorer Quick Start folder. |
| T1573.001 Symmetric Cryptography |
CORESHELL C2 messages are encrypted with custom stream ciphers using six-byte or eight-byte keys. |
| T1680 Local Storage Discovery |
CORESHELL collects the volume serial number from the victim and sends the information to its C2 server. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.