Malware.View on attack.mitre.org
SharpDisco is a dropper developed in C# that has been used by MoustachedBouncer since at least 2020 to load malicious plugins.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
SharpDisco has dropped a recent-files stealer plugin to `C:\Users\Public\WinSrcNT\It11.exe`. |
| T1041 Exfiltration Over C2 Channel |
SharpDisco can load a plugin to exfiltrate stolen files to SMB shares also used in C2. |
| T1053.005 Scheduled Task |
SharpDisco can create scheduled tasks to execute reverse shells that read and write data to and from specified SMB shares. |
| T1059.003 Windows Command Shell |
SharpDisco can use `cmd.exe` to execute plugins and to send command output to specified SMB shares. |
| T1071.002 File Transfer Protocols |
SharpDisco has the ability to transfer data between SMB shares. |
| T1083 File and Directory Discovery |
SharpDisco can identify recently opened files by using an LNK format parser to extract the original file path from LNK files found in either `%USERPROFILE%\Recent` (Windows XP) or `%APPDATA%\Microsoft\Windows\Recent` (newer Windows versions) . |
| T1105 Ingress Tool Transfer |
SharpDisco has been used to download a Python interpreter to `C:\Users\Public\WinTN\WinTN.exe` as well as other plugins from external sources. |
| T1106 Native API |
SharpDisco can leverage Native APIs through plugins including `GetLogicalDrives`. |
| T1120 Peripheral Device Discovery |
SharpDisco has dropped a plugin to monitor external drives to `C:\Users\Public\It3.exe`. |
| T1564.003 Hidden Window |
SharpDisco can hide windows using `ProcessWindowStyle.Hidden`. |
| T1680 Local Storage Discovery |
SharpDisco can use a plugin to enumerate system drives. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.