Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
SVCReady can collect data from an infected host. |
| T1012 Query Registry |
SVCReady can search for the `HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System` Registry key to gather system information. |
| T1027 Obfuscated Files or Information |
SVCReady can encrypt victim data with an RC4 cipher. |
| T1033 System Owner/User Discovery |
SVCReady can collect the username from an infected host. |
| T1036.004 Masquerade Task or Service |
SVCReady has named a task `RecoveryExTask` as part of its persistence activity. |
| T1041 Exfiltration Over C2 Channel |
SVCReady can send collected data in JSON format to its C2 server. |
| T1047 Windows Management Instrumentation |
SVCReady can use `WMI` queries to detect the presence of a virtual machine environment. |
| T1053.005 Scheduled Task |
SVCReady can create a scheduled task named `RecoveryExTask` to gain persistence. |
| T1057 Process Discovery |
SVCReady can collect a list of running processes from an infected host. |
| T1059.005 Visual Basic |
SVCReady has used VBA macros to execute shellcode. |
| T1071.001 Web Protocols |
SVCReady can communicate with its C2 servers via HTTP. |
| T1082 System Information Discovery |
SVCReady has the ability to collect information such as computer name, computer manufacturer, BIOS, operating system, and firmware, including through the use of `systeminfo.exe`. |
| T1105 Ingress Tool Transfer |
SVCReady has the ability to download additional tools such as the RedLine Stealer to an infected host. |
| T1106 Native API |
SVCReady can use Windows API calls to gather information from an infected host. |
| T1113 Screen Capture |
SVCReady can take a screenshot from an infected host. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.