Malware.View on attack.mitre.org
ZxShell is a remote administration tool and backdoor that can be downloaded from the Internet, particularly from Chinese hacker websites. It has been used since at least 2004.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
ZxShell can transfer files from a compromised host. |
| T1007 System Service Discovery |
ZxShell can check the services on the system. |
| T1012 Query Registry |
ZxShell can query the netsvc group value data located in the svchost group Registry key. |
| T1021.001 Remote Desktop Protocol |
ZxShell has remote desktop functionality. |
| T1021.005 VNC |
ZxShell supports functionality for VNC sessions. |
| T1033 System Owner/User Discovery |
ZxShell can collect the owner and organization information from the target workstation. |
| T1046 Network Service Discovery |
ZxShell can launch port scans. |
| T1055.001 Dynamic-link Library Injection |
ZxShell is injected into a shared SVCHOST process. |
| T1056.001 Keylogging |
ZxShell has a feature to capture a remote computer's keystrokes using a keylogger. |
| T1056.004 Credential API Hooking |
ZxShell hooks several API functions to spawn system threads. |
| T1057 Process Discovery |
ZxShell has a command, ps, to obtain a listing of processes on the system. |
| T1059.003 Windows Command Shell |
ZxShell can launch a reverse command shell. |
| T1070.004 File Deletion |
ZxShell can delete files from the system. |
| T1071.001 Web Protocols |
ZxShell has used HTTP for C2 connections. |
| T1071.002 File Transfer Protocols |
ZxShell has used FTP for C2 connections. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.