Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1021.002 SMB/Windows Admin Shares |
Conficker variants spread through NetBIOS share propagation. |
| T1027 Obfuscated Files or Information |
Conficker has obfuscated its code to prevent its removal from host machines. |
| T1046 Network Service Discovery |
Conficker scans for other machines to infect. |
| T1091 Replication Through Removable Media |
Conficker variants used the Windows AUTORUN feature to spread through USB propagation. |
| T1105 Ingress Tool Transfer |
Conficker downloads an HTTP server to the infected machine. |
| T1112 Modify Registry |
Conficker adds keys to the Registry at |
| T1124 System Time Discovery |
Conficker uses the current UTC victim system date for domain generation and connects to time servers to determine the current date. |
| T1210 Exploitation of Remote Services |
Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request. |
| T1490 Inhibit System Recovery |
Conficker resets system restore points and deletes backup files. |
| T1543.003 Windows Service |
Conficker copies itself into the |
| T1547.001 Registry Run Keys / Startup Folder |
Conficker adds Registry Run keys to establish persistence. |
| T1568.002 Domain Generation Algorithms |
Conficker has used a DGA that seeds with the current UTC victim system date to generate domains. |
| T1685 Disable or Modify Tools |
Conficker terminates various services related to system security and Windows. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.