Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.009 Embedded Payloads |
DEADWOOD contains an embedded, AES-encrypted payload labeled |
| T1027.013 Encrypted/Encoded File |
DEADWOOD contains an embedded, AES-encrypted resource named |
| T1036.004 Masquerade Task or Service |
DEADWOOD will attempt to masquerade its service execution using benign-looking names such as |
| T1124 System Time Discovery |
DEADWOOD will set a timestamp value to determine when wiping functionality starts. When the timestamp is met on the system, a trigger file is created on the operating system allowing for execution to proceed. If the timestamp is in the past, the wiper will execute immediately. |
| T1140 Deobfuscate/Decode Files or Information |
DEADWOOD XORs some strings within the binary using the value |
| T1485 Data Destruction |
DEADWOOD overwrites files on victim systems with random data to effectively destroy them. |
| T1531 Account Access Removal |
DEADWOOD changes the password for local and domain users via |
| T1561.001 Disk Content Wipe |
DEADWOOD deletes files following overwriting them with random data. |
| T1561.002 Disk Structure Wipe |
DEADWOOD opens and writes zeroes to the first 512 bytes of each drive, deleting the MBR. DEADWOOD then sends the control code |
| T1569.002 Service Execution |
DEADWOOD can be executed as a service using various names, such as |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.