Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
metaMain can collect files and system information from a compromised host. |
| T1027.013 Encrypted/Encoded File |
metaMain's module file has been encrypted via XOR. |
| T1033 System Owner/User Discovery |
metaMain can collect the username from a compromised host. |
| T1041 Exfiltration Over C2 Channel |
metaMain can upload collected files and data to its C2 server. |
| T1055 Process Injection |
metaMain can inject the loader file, Speech02.db, into a process. |
| T1056 Input Capture |
metaMain can log mouse events. |
| T1056.001 Keylogging |
metaMain has the ability to log keyboard events. |
| T1057 Process Discovery |
metaMain can enumerate the processes that run on the platform. |
| T1070.004 File Deletion |
metaMain has deleted collected items after uploading the content to its C2 server. |
| T1070.006 Timestomp |
metaMain can change the `CreationTime`, `LastAccessTime`, and `LastWriteTime` file time attributes when executed with `SYSTEM` privileges. |
| T1071.001 Web Protocols |
metaMain can use HTTP for C2 communications. |
| T1074.001 Local Data Staging |
metaMain has stored the collected system files in a working directory. |
| T1082 System Information Discovery |
metaMain can collect the computer name from a compromised host. |
| T1083 File and Directory Discovery |
metaMain can recursively enumerate files in an operator-provided directory. |
| T1090.001 Internal Proxy |
metaMain can create a named pipe to listen for and send data to a named pipe-based C2 server. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.