Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
AppleSeed can collect data on a compromised host. |
| T1008 Fallback Channels |
AppleSeed can use a second channel for C2 when the primary channel is in upload mode. |
| T1016 System Network Configuration Discovery |
AppleSeed can identify the IP of a targeted system. |
| T1025 Data from Removable Media |
AppleSeed can find and collect data from removable media devices. |
| T1027 Obfuscated Files or Information |
AppleSeed has the ability to Base64 encode its payload and custom encrypt API calls. |
| T1027.002 Software Packing |
AppleSeed has used UPX packers for its payload DLL. |
| T1030 Data Transfer Size Limits |
AppleSeed has divided files if the size is 0x1000000 bytes or more. |
| T1036 Masquerading |
AppleSeed can disguise JavaScript files as PDFs. |
| T1036.005 Match Legitimate Resource Name or Location |
AppleSeed has the ability to rename its payload to ESTCommon.dll to masquerade as a DLL belonging to ESTsecurity. |
| T1041 Exfiltration Over C2 Channel |
AppleSeed can exfiltrate files via the C2 channel. |
| T1056.001 Keylogging |
AppleSeed can use |
| T1057 Process Discovery |
AppleSeed can enumerate the current process on a compromised host. |
| T1059.001 PowerShell |
AppleSeed has the ability to execute its payload via PowerShell. |
| T1059.007 JavaScript |
AppleSeed has the ability to use JavaScript to execute PowerShell. |
| T1070.004 File Deletion |
AppleSeed can delete files from a compromised host after they are exfiltrated. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.