Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
SUPERNOVA contained Base64-encoded strings. |
| T1036.005 Match Legitimate Resource Name or Location |
SUPERNOVA has masqueraded as a legitimate SolarWinds DLL. |
| T1071.001 Web Protocols |
SUPERNOVA had to receive an HTTP GET request containing a specific set of parameters in order to execute. |
| T1203 Exploitation for Client Execution |
SUPERNOVA was installed via exploitation of a SolarWinds Orion API authentication bypass vulnerability (CVE-2020-10148). |
| T1505.003 Web Shell |
SUPERNOVA is a Web shell. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.