Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
WellMail can exfiltrate files from the victim machine. |
| T1016 System Network Configuration Discovery |
WellMail can identify the IP address of the victim system. |
| T1033 System Owner/User Discovery |
WellMail can identify the current username on the victim system. |
| T1095 Non-Application Layer Protocol |
WellMail can use TCP for C2 communications. |
| T1105 Ingress Tool Transfer |
WellMail can receive data and executable scripts from C2. |
| T1140 Deobfuscate/Decode Files or Information |
WellMail can decompress scripts received from C2. |
| T1560 Archive Collected Data |
WellMail can archive files on the compromised host. |
| T1571 Non-Standard Port |
WellMail has been observed using TCP port 25, without using SMTP, to leverage an open port for secure command and control communications. |
| T1573.002 Asymmetric Cryptography |
WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.