Malware.View on attack.mitre.org
POWRUNER is a PowerShell script that sends and receives commands to and from the C2 server.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
POWRUNER may query the Registry by running |
| T1016 System Network Configuration Discovery |
POWRUNER may collect network configuration data by running |
| T1033 System Owner/User Discovery |
POWRUNER may collect information about the currently logged in user by running |
| T1047 Windows Management Instrumentation |
POWRUNER may use WMI when collecting information about a victim. |
| T1049 System Network Connections Discovery |
POWRUNER may collect active network connections by running |
| T1053.005 Scheduled Task |
POWRUNER persists through a scheduled task that executes it every minute. |
| T1057 Process Discovery |
POWRUNER may collect process information by running |
| T1059.001 PowerShell |
POWRUNER is written in PowerShell. |
| T1059.003 Windows Command Shell |
POWRUNER can execute commands from its C2 server. |
| T1069.001 Local Groups |
POWRUNER may collect local group information by running |
| T1069.002 Domain Groups |
POWRUNER may collect domain group information by running |
| T1071.001 Web Protocols |
POWRUNER can use HTTP for C2 communications. |
| T1071.004 DNS |
POWRUNER can use DNS for C2 communications. |
| T1082 System Information Discovery |
POWRUNER may collect information about the system by running |
| T1083 File and Directory Discovery |
POWRUNER may enumerate user directories on a victim. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.