Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
LookBack can enumerate services on the victim machine. |
| T1036.005 Match Legitimate Resource Name or Location |
LookBack has a C2 proxy tool that masquerades as |
| T1057 Process Discovery |
LookBack can list running processes. |
| T1059.003 Windows Command Shell |
LookBack executes the |
| T1059.005 Visual Basic |
LookBack has used VBA macros in Microsoft Word attachments to drop additional files to the host. |
| T1070.004 File Deletion |
LookBack removes itself after execution and can delete files on the system. |
| T1071.001 Web Protocols |
LookBack’s C2 proxy tool sends data to a C2 server over HTTP. |
| T1083 File and Directory Discovery |
LookBack can retrieve file listings from the victim machine. |
| T1095 Non-Application Layer Protocol |
LookBack uses a custom binary protocol over sockets for C2 communications. |
| T1113 Screen Capture |
LookBack can take desktop screenshots. |
| T1140 Deobfuscate/Decode Files or Information |
LookBack has a function that decrypts malicious data. |
| T1489 Service Stop |
LookBack can kill processes and delete services. |
| T1529 System Shutdown/Reboot |
LookBack can shutdown and reboot the victim machine. |
| T1547.001 Registry Run Keys / Startup Folder |
LookBack sets up a Registry Run key to establish a persistence mechanism. |
| T1573.001 Symmetric Cryptography |
LookBack uses a modified version of RC4 for data transfer. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.