Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
DEADEYE can discover the DNS domain name of a targeted system. |
| T1027.009 Embedded Payloads |
The DEADEYE.EMBED variant of DEADEYE has the ability to embed payloads inside of a compiled binary. |
| T1027.013 Encrypted/Encoded File |
DEADEYE has encrypted its payload. |
| T1036.004 Masquerade Task or Service |
DEADEYE has used `schtasks /change` to modify scheduled tasks including `\Microsoft\Windows\PLA\Server Manager Performance Monitor`, `\Microsoft\Windows\Ras\ManagerMobility, \Microsoft\Windows\WDI\SrvSetupResults`, and `\Microsoft\Windows\WDI\USOShared`. |
| T1059.003 Windows Command Shell |
DEADEYE can run `cmd /c copy /y /b C:\Users\public\syslog_6-*.dat C:\Users\public\syslog.dll` to combine separated sections of code into a single DLL prior to execution. |
| T1082 System Information Discovery |
DEADEYE can enumerate a victim computer's volume serial number and host name. |
| T1106 Native API |
DEADEYE can execute the `GetComputerNameA` and `GetComputerNameExA` WinAPI functions. |
| T1140 Deobfuscate/Decode Files or Information |
DEADEYE has the ability to combine multiple sections of a binary which were broken up to evade detection into a single .dll prior to execution. |
| T1218.007 Msiexec |
DEADEYE can use `msiexec.exe` for execution of malicious DLL. |
| T1218.011 Rundll32 |
DEADEYE can use `rundll32.exe` for execution of living off the land binaries (lolbin) such as `SHELL32.DLL`. |
| T1480 Execution Guardrails |
DEADEYE can ensure it executes only on intended systems by identifying the victim's volume serial number, hostname, and/or DNS domain. |
| T1564.004 NTFS File Attributes |
The DEADEYE.EMBED variant of DEADEYE can embed its payload in an alternate data stream of a local file. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.