Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
Carbon enumerates values in the Registry. |
| T1016 System Network Configuration Discovery |
Carbon can collect the IP address of the victims and other computers on the network using the commands: |
| T1018 Remote System Discovery |
Carbon uses the |
| T1027 Obfuscated Files or Information |
Carbon encrypts configuration files and tasks for the malware to complete using CAST-128 algorithm. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
Carbon uses HTTP to send data to the C2 server. |
| T1049 System Network Connections Discovery |
Carbon uses the |
| T1053.005 Scheduled Task |
Carbon creates several tasks for later execution to continue persistence on the victim’s machine. |
| T1055.001 Dynamic-link Library Injection |
Carbon has a command to inject code into a process. |
| T1057 Process Discovery |
Carbon can list the processes on the victim’s machine. |
| T1069 Permission Groups Discovery |
Carbon uses the |
| T1071.001 Web Protocols |
Carbon can use HTTP in C2 communications. |
| T1074.001 Local Data Staging |
Carbon creates a base directory that contains the files and folders that are collected. |
| T1095 Non-Application Layer Protocol |
Carbon uses TCP and UDP for C2. |
| T1102 Web Service |
Carbon can use Pastebin to receive C2 commands. |
| T1124 System Time Discovery |
Carbon uses the command |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.