Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
DUSTTRAP can gather data from infected systems. |
| T1010 Application Window Discovery |
DUSTTRAP can enumerate running application windows. |
| T1012 Query Registry |
DUSTTRAP can enumerate Registry items. |
| T1016 System Network Configuration Discovery |
DUSTTRAP can enumerate infected system network information. |
| T1018 Remote System Discovery |
DUSTTRAP can use `ping` to identify remote hosts within the victim network. |
| T1027.009 Embedded Payloads |
DUSTTRAP contains additional embedded DLLs and configuration files that are loaded into memory during execution. |
| T1027.013 Encrypted/Encoded File |
DUSTTRAP begins with an initial launcher that decrypts an AES-128-CFB encrypted file on disk and executes it in memory. |
| T1041 Exfiltration Over C2 Channel |
DUSTTRAP can exfiltrate collected data over C2 channels. |
| T1055 Process Injection |
DUSTTRAP compromises the `.text` section of a legitimate system DLL in `%windir%` to hold the contents of retrieved plug-ins. |
| T1056.001 Keylogging |
DUSTTRAP can perform keylogging operations. |
| T1057 Process Discovery |
DUSTTRAP can enumerate running processes. |
| T1059.003 Windows Command Shell |
DUSTTRAP can execute commands via `cmd.exe`. |
| T1070 Indicator Removal |
DUSTTRAP restores the `.text` section of compromised DLLs after malicious code is loaded into memory and before the file is closed. |
| T1070.005 Network Share Connection Removal |
DUSTTRAP can remove network shares from infected systems. |
| T1082 System Information Discovery |
DUSTTRAP reads the value of the infected system's `HKLM\SYSTEM\Microsoft\Cryptography\MachineGUID` value. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.