Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
BADFLICK has uploaded files from victims' machines. |
| T1016 System Network Configuration Discovery |
BADFLICK has captured victim IP address details. |
| T1082 System Information Discovery |
BADFLICK has captured victim computer name, memory space, and CPU details. |
| T1083 File and Directory Discovery |
BADFLICK has searched for files on the infected host. |
| T1105 Ingress Tool Transfer |
BADFLICK has download files from its C2 server. |
| T1140 Deobfuscate/Decode Files or Information |
BADFLICK can decode shellcode using a custom rotating XOR cipher. |
| T1204.002 Malicious File |
BADFLICK has relied upon users clicking on a malicious attachment delivered through spearphishing. |
| T1497.003 Time Based Checks |
BADFLICK has delayed communication to the actor-controlled IP address by 5 minutes. |
| T1560.002 Archive via Library |
BADFLICK has compressed data using the aPLib compression library. |
| T1566.001 Spearphishing Attachment |
BADFLICK has been distributed via spearphishing campaigns containing malicious Microsoft Word documents. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.