Malware.View on attack.mitre.org
Final1stspy is a dropper family that has been used to deliver DOGCALL.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Final1stspy obfuscates strings with base64 encoding. |
| T1057 Process Discovery |
Final1stspy obtains a list of running processes. |
| T1071.001 Web Protocols |
Final1stspy uses HTTP for C2. |
| T1082 System Information Discovery |
Final1stspy obtains victim Microsoft Windows version information and CPU architecture. |
| T1140 Deobfuscate/Decode Files or Information |
Final1stspy uses Python code to deobfuscate base64-encoded strings. |
| T1547.001 Registry Run Keys / Startup Folder |
Final1stspy creates a Registry Run key to establish persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.