Malware.View on attack.mitre.org
Cannon is a Trojan with variants written in C# and Delphi. It was first observed in April 2018.
| Technique | Procedure example |
|---|---|
| T1033 System Owner/User Discovery |
Cannon can gather the username from the system. |
| T1041 Exfiltration Over C2 Channel |
Cannon exfiltrates collected data over email via SMTP/S and POP3/S C2 channels. |
| T1057 Process Discovery |
Cannon can obtain a list of processes running on the system. |
| T1071.003 Mail Protocols |
Cannon uses SMTP/S and POP3/S for C2 communications by sending and receiving emails. |
| T1082 System Information Discovery |
Cannon can gather system information from the victim’s machine such as the OS version, and machine name. |
| T1083 File and Directory Discovery |
Cannon can obtain victim drive information as well as a list of folders in C:\Program Files. |
| T1105 Ingress Tool Transfer |
Cannon can download a payload for execution. |
| T1113 Screen Capture |
Cannon can take a screenshot of the desktop. |
| T1124 System Time Discovery |
Cannon can collect the current time zone information from the victim’s machine. |
| T1547.004 Winlogon Helper DLL |
Cannon adds the Registry key |
| T1680 Local Storage Discovery |
Cannon can gather drive information from the victim's machine. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.