Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
|
| T1016 System Network Configuration Discovery |
Lizar has retrieved network information from a compromised host, such as the MAC address. |
| T1027 Obfuscated Files or Information |
Lizar has obfuscated the fingerprint of the victim system, the local IP address, and the Fowler-Noll-V 1 (FNV-1) hash of the local IP address using an XOR operation. The data is then sent to the C2 server. |
| T1033 System Owner/User Discovery |
Lizar can collect the username from the system. |
| T1049 System Network Connections Discovery |
Lizar has a plugin to retrieve information about all active network sessions on the infected server. |
| T1055 Process Injection |
Lizar can migrate the loader into another process. |
| T1055.001 Dynamic-link Library Injection |
Lizar has used the PowerKatz plugin that can be loaded into the address space of a PowerShell process through reflective DLL loading. |
| T1055.002 Portable Executable Injection |
Lizar can execute PE files in the address space of the specified process. |
| T1057 Process Discovery |
Lizar has a plugin designed to obtain a list of processes. |
| T1059.001 PowerShell |
Lizar has used PowerShell scripts. |
| T1059.003 Windows Command Shell |
Lizar has a command to open the command-line on the infected system. |
| T1059.006 Python |
Lizar has used Python scripts (ps2x.py script and ps2p.py) to execute files on remote hosts using the Impacket library. |
| T1082 System Information Discovery |
Lizar can collect the computer name from the machine. |
| T1087.003 Email Account |
Lizar can collect email accounts from Microsoft Outlook and Mozilla Thunderbird. |
| T1095 Non-Application Layer Protocol |
Lizar has used a raw TCP connection to communicate with the C2 server. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.