Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
TinyTurla can upload files from a compromised host. |
| T1008 Fallback Channels |
TinyTurla can go through a list of C2 server IPs and will try to register with each until one responds. |
| T1012 Query Registry |
TinyTurla can query the Registry for its configuration information. |
| T1027.011 Fileless Storage |
TinyTurla can save its configuration parameters in the Registry. |
| T1029 Scheduled Transfer |
TinyTurla contacts its C2 based on a scheduled timing set in its configuration. |
| T1036.004 Masquerade Task or Service |
TinyTurla has mimicked an existing Windows service by being installed as |
| T1036.005 Match Legitimate Resource Name or Location |
TinyTurla has been deployed as `w64time.dll` to appear legitimate. |
| T1059.003 Windows Command Shell |
TinyTurla has been installed using a .bat file. |
| T1071.001 Web Protocols |
TinyTurla can use HTTPS in C2 communications. |
| T1105 Ingress Tool Transfer |
TinyTurla has the ability to act as a second-stage dropper used to infect the system with additional malware. |
| T1106 Native API |
TinyTurla has used `WinHTTP`, `CreateProcess`, and other APIs for C2 communications and other functions. |
| T1112 Modify Registry |
TinyTurla can set its configuration parameters in the Registry. |
| T1569.002 Service Execution |
TinyTurla can install itself as a service on compromised machines. |
| T1573.002 Asymmetric Cryptography |
TinyTurla has the ability to encrypt C2 traffic with SSL/TLS. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.