Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
SoreFang can collect the TCP/IP, DNS, DHCP, and network adapter configuration on a compromised host via |
| T1027 Obfuscated Files or Information |
SoreFang has the ability to encode and RC6 encrypt data sent to C2. |
| T1053.005 Scheduled Task |
SoreFang can gain persistence through use of scheduled tasks. |
| T1057 Process Discovery |
SoreFang can enumerate processes on a victim machine through use of Tasklist. |
| T1069.002 Domain Groups |
SoreFang can enumerate domain groups by executing |
| T1071.001 Web Protocols |
SoreFang can use HTTP in C2 communications. |
| T1082 System Information Discovery |
SoreFang can collect the hostname, operating system configuration, and product ID on victim machines by executing Systeminfo. |
| T1083 File and Directory Discovery |
SoreFang has the ability to list directories. |
| T1087.001 Local Account |
SoreFang can collect usernames from the local system via |
| T1087.002 Domain Account |
SoreFang can enumerate domain accounts via |
| T1105 Ingress Tool Transfer |
SoreFang can download additional payloads from C2. |
| T1140 Deobfuscate/Decode Files or Information |
SoreFang can decode and decrypt exfiltrated data sent to C2. |
| T1190 Exploit Public-Facing Application |
SoreFang can gain access by exploiting a Sangfor SSL VPN vulnerability that allows for the placement and delivery of malicious update binaries. |
| T1680 Local Storage Discovery |
SoreFang can collect disk space information on victim machines by executing Systeminfo. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.