Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
RTM strings, network data, configuration, and modules are encrypted with a modified RC4 algorithm. |
| T1027.015 Compression |
RTM has been delivered to targets as various archive files including ZIP, 7-ZIP, and RAR. |
| T1033 System Owner/User Discovery |
RTM can obtain the victim username and permissions. |
| T1036 Masquerading |
RTM has been delivered as archived Windows executable files masquerading as PDF documents. |
| T1036.004 Masquerade Task or Service |
RTM has named the scheduled task it creates "Windows Update". |
| T1053.005 Scheduled Task |
RTM tries to add a scheduled task to establish persistence. |
| T1056.001 Keylogging |
RTM can record keystrokes from both the keyboard and virtual keyboard. |
| T1057 Process Discovery |
RTM can obtain information about process integrity levels. |
| T1059.003 Windows Command Shell |
RTM uses the command line and rundll32.exe to execute. |
| T1070.004 File Deletion |
RTM can delete all files created during its execution. |
| T1070.009 Clear Persistence |
RTM has the ability to remove Registry entries that it created for persistence. |
| T1071.001 Web Protocols |
RTM has initiated connections to external domains using HTTPS. |
| T1082 System Information Discovery |
RTM can obtain the computer name, OS version, and default language identifier. |
| T1083 File and Directory Discovery |
RTM can check for specific files and directories associated with virtualization and malware analysis. |
| T1102.001 Dead Drop Resolver |
RTM has used an RSS feed on Livejournal to update a list of encrypted C2 server names. RTM has also hidden Pony C2 server IP addresses within transactions on the Bitcoin and Namecoin blockchain. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.