Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
JPIN can list running services. |
| T1012 Query Registry |
JPIN can enumerate Registry keys. |
| T1016 System Network Configuration Discovery |
JPIN can obtain network information, including DNS, IP, and proxies. |
| T1027 Obfuscated Files or Information |
A JPIN uses a encrypted and compressed payload that is disguised as a bitmap within the resource section of the installer. |
| T1033 System Owner/User Discovery |
JPIN can obtain the victim user name. |
| T1055 Process Injection |
JPIN can inject content into lsass.exe to load a module. |
| T1056.001 Keylogging |
JPIN contains a custom keylogger. |
| T1057 Process Discovery |
JPIN can list running processes. |
| T1059.003 Windows Command Shell |
JPIN can use the command-line utility cacls.exe to change file permissions. |
| T1069.001 Local Groups |
JPIN can obtain the permissions of the victim user. |
| T1070.004 File Deletion |
JPIN's installer/uninstaller component deletes itself if it encounters a version of Windows earlier than Windows XP or identifies security-related processes running. |
| T1071.002 File Transfer Protocols |
JPIN can communicate over FTP. |
| T1071.003 Mail Protocols |
JPIN can send email over SMTP. |
| T1082 System Information Discovery |
JPIN can obtain system information such as OS version and disk space. |
| T1083 File and Directory Discovery |
JPIN can enumerate drives and their types. It can also change file permissions using cacls.exe. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.