Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
BRUSHFIRE has the ability to exfiltrate data on-demand through executing commands obtained via monitoring for specially crafted packets and sending output back in an embedded SSL response. |
| T1140 Deobfuscate/Decode Files or Information |
BRUSHFIRE has decrypted XOR strings prior to execution. |
| T1205 Traffic Signaling |
BRUSHFIRE has monitored inbound VPN traffic to compromised appliances until specific inbound packets contain a specific magic string/pattern instead of external beaconing. |
| T1620 Reflective Code Loading |
BRUSHFIRE has executed its commands within memory and is not saved on disk. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.