Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1059.001 PowerShell |
Ferocious can use PowerShell scripts for execution. |
| T1059.005 Visual Basic |
Ferocious has the ability to use Visual Basic scripts for execution. |
| T1070.004 File Deletion |
Ferocious can delete files from a compromised host. |
| T1082 System Information Discovery |
Ferocious can use |
| T1112 Modify Registry |
Ferocious has the ability to add a Class ID in the current user Registry hive to enable persistence mechanisms. |
| T1120 Peripheral Device Discovery |
Ferocious can run |
| T1497.001 System Checks |
Ferocious can run anti-sandbox checks using the Microsoft Excel 4.0 function |
| T1518.001 Security Software Discovery |
Ferocious has checked for AV software as part of its persistence process. |
| T1546.015 Component Object Model Hijacking |
Ferocious can use COM hijacking to establish persistence. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.