Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
ChChes copies itself to an .exe file with a filename that is likely intended to imitate Norton Antivirus but has several letters reversed (e.g. notron.exe). |
| T1057 Process Discovery |
ChChes collects its process identifier (PID) on the victim. |
| T1071.001 Web Protocols |
ChChes communicates to its C2 server over HTTP and embeds data within the Cookie HTTP header. |
| T1082 System Information Discovery |
ChChes collects the victim hostname, window resolution, and Microsoft Windows version. |
| T1083 File and Directory Discovery |
ChChes collects the victim's %TEMP% directory path and version of Internet Explorer. |
| T1105 Ingress Tool Transfer |
ChChes is capable of downloading files, including additional modules. |
| T1132.001 Standard Encoding |
ChChes can encode C2 data with a custom technique that utilizes Base64. |
| T1547.001 Registry Run Keys / Startup Folder |
ChChes establishes persistence by adding a Registry Run key. |
| T1553.002 Code Signing |
ChChes samples were digitally signed with a certificate originally used by Hacking Team that was later leaked and subsequently revoked. |
| T1555.003 Credentials from Web Browsers |
ChChes steals credentials stored inside Internet Explorer. |
| T1573.001 Symmetric Cryptography |
ChChes can encrypt C2 traffic with AES or RC4. |
| T1685 Disable or Modify Tools |
ChChes can alter the victim's proxy configuration. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.