Malware.View on attack.mitre.org
ccf32 is data collection malware that has been used since at least February 2019, most notably during the FunnyDream campaign; there is also a similar x64 version.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
ccf32 can collect files from a compromised host. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
ccf32 can upload collected data and files to an FTP server. |
| T1053.005 Scheduled Task |
ccf32 can run on a daily basis using a scheduled task. |
| T1059.003 Windows Command Shell |
ccf32 has used `cmd.exe` for archiving data and deleting files. |
| T1070.004 File Deletion |
ccf32 can delete files and folders from compromised machines. |
| T1074.001 Local Data Staging |
ccf32 can temporarily store files in a hidden directory on the local host. |
| T1074.002 Remote Data Staging |
ccf32 has copied files to a remote machine infected with Chinoxy or another backdoor. |
| T1083 File and Directory Discovery |
ccf32 can parse collected files to identify specific file extensions. |
| T1119 Automated Collection |
ccf32 can be used to automatically collect files from a compromised host. |
| T1124 System Time Discovery |
ccf32 can determine the local time on targeted machines. |
| T1560.001 Archive via Utility |
ccf32 has used `xcopy \\<target_host>\c$\users\public\path.7z c:\users\public\bin\<target_host>.7z /H /Y` to archive collected files. |
| T1564.001 Hidden Files and Directories |
ccf32 has created a hidden directory on targeted systems, naming it after the current local time (year, month, and day). |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.