Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1047 Windows Management Instrumentation |
TAMECAT has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| T1059.001 PowerShell |
TAMECAT has used PowerShell to download and run additional content. |
| T1059.003 Windows Command Shell |
TAMECAT has used `cmd.exe` to run the `curl` command. |
| T1059.005 Visual Basic |
TAMECAT has used VBScript to query anti-virus products. |
| T1071.001 Web Protocols |
TAMECAT has used HTTP for C2 communications. |
| T1105 Ingress Tool Transfer |
TAMECAT has used `wget` and `curl` to download additional content. |
| T1132.001 Standard Encoding |
TAMECAT has encoded C2 traffic with Base64. |
| T1518.001 Security Software Discovery |
TAMECAT has used Windows Management Instrumentation (WMI) to check for anti-virus products. |
| T1573.001 Symmetric Cryptography |
TAMECAT has used AES to encrypt C2 traffic. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.