Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.009 Embedded Payloads |
DUSTPAN decrypts and executes an embedded payload. |
| T1027.013 Encrypted/Encoded File |
DUSTPAN decrypts an embedded payload. |
| T1036.005 Match Legitimate Resource Name or Location |
DUSTPAN is often disguised as a legitimate Windows binary such as `w3wp.exe` or `conn.exe`. |
| T1055.002 Portable Executable Injection |
DUSTPAN can inject its decrypted payload into another process. |
| T1140 Deobfuscate/Decode Files or Information |
DUSTPAN decodes and decrypts embedded payloads. |
| T1543.003 Windows Service |
DUSTPAN can persist as a Windows Service in operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.